Engineering PapersSearch

SEARCH · Engineering Papers

Results for “Integrated formal methods”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

NASA Astronauts on Soyuz: Experience and Lessons for the Future

The U. S., Russia, and, China have each addressed the question of human-rating spacecraft. NASA's operational experience with human-rating primarily resides with Mercury, Gemini, Apollo, Space Shuttle, and International Space Station. NASA s latest developmental experience includes Constellation, X38, X33, and the Orbital Space Plane. If domestic commercial crew vehicles are used to transport astronauts to and from space, Soyuz is another example of methods that could be used to human-rate a spacecraft and to work with commercial spacecraft providers. For Soyuz, NASA's normal assurance practices were adapted. Building on NASA's Soyuz experience, this report contends all past, present, and future vehicles rely on a range of methods and techniques for human-rating assurance, the components of which include: requirements, conceptual development, prototype evaluations, configuration management, formal development reviews (safety, design, operations), component/system ground-testing, integrated flight tests, independent assessments, and launch readiness reviews. When constraints (cost, schedule, international) limit the depth/breadth of one or more preferred assurance means, ways are found to bolster the remaining areas. This report provides information exemplifying the above safety assurance model for consideration with commercial or foreign-government-designed spacecraft. Topics addressed include: U.S./Soviet-Russian government/agency agreements and engineering/safety assessments performed with lessons learned in historic U.S./Russian joint space ventures

Source record

Towards a Theory for Integration of Mathematical Verification and Empirical Testing

From the viewpoint of a project manager responsible for the V&V (verification and validation) of a software system, mathematical verification techniques provide a possibly useful orthogonal dimension to otherwise standard empirical testing. However, the value they add to an empirical testing regime both in terms of coverage and in fault detection has been difficult to quantify. Furthermore, potential cost savings from replacing testing with mathematical verification techniques cannot be realized until the tradeoffs and synergies can be formulated. Integration of formal verification with empirical testing is also difficult because the idealized view of mathematical verification providing a correctness proof with total coverage is unrealistic and does not reflect the limitations imposed by computational complexity of mathematical techniques. This paper first describes a framework based on software reliability and formalized fault models for a theory of software design fault detection - and hence the utility of various tools for debugging. It then describes a utility model for integrating mathematical and empirical techniques with respect to fault detection and coverage analysis. It then considers the optimal combination of black-box testing, white-box (structural) testing, and formal methods in V&V of a software system. Using case studies from NASA software systems, it then demonstrates how this utility model can be used in practice.

Lowry, Michael

Heterogeneous Multi-Domain Dataset Synthesis to Facilitate Privacy and Risk Assessments in Smart City IoT

The emergence of the Smart Cities paradigm and the rapid expansion and integration of Internet of Things (IoT) technologies within this context have created unprecedented opportunities for high-resolution behavioral analytics, urban optimization, and context-aware services. However, this same proliferation intensifies privacy risks, particularly those arising from cross-modal data linkage across heterogeneous sensing platforms. To address these challenges, this paper introduces a comprehensive, statistically grounded framework for generating synthetic, multimodal IoT datasets tailored to Smart City research. The framework produces behaviorally plausible synthetic data suitable for preliminary privacy risk assessment and as a benchmark for future re-identification studies, as well as for evaluating algorithms in mobility modeling, urban informatics, and privacy-enhancing technologies. As part of our approach, we formalize probabilistic methods for synthesizing three heterogeneous and operationally relevant data streams—cellular mobility traces, payment terminal transaction logs, and Smart Retail nutrition records—capturing the behaviors of a large number of synthetically generated urban residents over a 12-week period. The framework integrates spatially explicit merchant selection using K-Dimensional (KD)-tree nearest-neighbor algorithms, temporally correlated anchor-based mobility simulation reflective of daily urban rhythms, and dietary-constraint filtering to preserve ecological validity in consumption patterns. In total, the system generates approximately 116 million mobility pings, 5.4 million transactions, and 1.9 million itemized purchases, yielding a reproducible benchmark for evaluating multimodal analytics, privacy-preserving computation, and secure IoT data-sharing protocols. To show the validity of this dataset, the underlying distributions of these residents were successfully validated against reported distributions in published research. We present preliminary uniqueness and cross-modal linkage indicators; comprehensive re-identification benchmarking against specific attack algorithms is planned as future work. This framework can be easily adapted to various scenarios of interest in Smart Cities and other IoT applications. By aligning methodological rigor with the operational needs of Smart City ecosystems, this work fills critical gaps in synthetic data generation for privacy-sensitive domains, including intelligent transportation systems, urban health informatics, and next-generation digital commerce infrastructures.

IoT

Design Methods and Practices for Fault Prevention and Management in Spacecraft

Integrated Systems Health Management (ISHM) is intended to become a critical capability for all space, lunar and planetary exploration vehicles and systems at NASA. Monitoring and managing the health state of diverse components, subsystems, and systems is a difficult task that will become more challenging when implemented for long-term, evolving deployments. A key technical challenge will be to ensure that the ISHM technologies are reliable, effective, and low cost, resulting in turn in safe, reliable, and affordable missions. To ensure safety and reliability, ISHM functionality, decisions and knowledge have to be incorporated into the product lifecycle as early as possible, and ISHM must be considered as an essential element of models developed and used in various stages during system design. During early stage design, many decisions and tasks are still open, including sensor and measurement point selection, modeling and model-checking, diagnosis, signature and data fusion schemes, presenting the best opportunity to catch and prevent potential failures and anomalies in a cost-effective way. Using appropriate formal methods during early design, the design teams can systematically explore risks without committing to design decisions too early. However, the nature of ISHM knowledge and data is detailed, relying on high-fidelity, detailed models, whereas the earlier stages of the product lifecycle utilize low-fidelity, high-level models of systems and their functionality. We currently lack the tools and processes necessary for integrating ISHM into the vehicle system/subsystem design. As a result, most existing ISHM-like technologies are retrofits that were done after the system design was completed. It is very expensive, and sometimes futile, to retrofit a system health management capability into existing systems. Last-minute retrofits result in unreliable systems, ineffective solutions, and excessive costs (e.g., Space Shuttle TPS monitoring which was considered only after 110 flights and the Columbia disaster). High false alarm or false negative rates due to substandard implementations hurt the credibility of the ISHM discipline. This paper presents an overview of the current state of ISHM design,and a review of formal design methods to make recommendations about possible approaches to enable the ISHM capabilities to be designed-in at the system-level, from the very beginning of the vehicle design process.

Tumer, Irem Y.

The Density Matrix of H20 - N2 In the Coordinate Representation: A Monte Carlo Calculation of the Far-Wing Line Shape

The far-wing line shape theory within the binary collision and quasistatic framework has been developed using the coordinate representation. Within this formalism, the main computational task is the evaluation of multidimensional integrals whose variables are the orientational angles needed to specify the initial and final positions of the system during transition processes. Using standard methods, one is able to evaluate the 7-dimensional integrations required for linear molecular systems, or the 7-dimensional integrations for more complicated asymmetric-top (or symmetric-top) molecular systems whose interaction potential contains cyclic coordinates. In order to obviate this latter restriction on the form of the interaction potential, a Monte Carlo method is used to evaluate the 9-dimensional integrations required for systems consisting of one asymmetric-top (or symmetric-top) and one linear molecule, such as H20-N2. Combined with techniques developed previously to deal with sophisticated potential models, one is able to implement realistic potentials for these systems and derive accurate, converged results for the far-wing line shapes and the corresponding absorption coefficients. Conversely, comparison of the far-wing absorption with experimental data can serve as a sensitive diagnostic tool in order to obtain detailed information on the short-range anisotropic dependence of interaction potentials.

Ma, Q.

Thermostructural tailoring of fiber composite structures

A significant area of interest in design of complex structures involves the study of multidisciplined problems. The coordination of several different intricate areas of study to obtain a particular design of a structure is a new and pressing area of research. In the past, each discipline would perform its task consecutively using the appropriate inputs from the other disciplines. This process usually required several time-consuming iterations to obtain a satisfactory design. The alternative pursued here is combining various participating disciplines and specified design requirements into a formal structural computer code. The main focus of this research is to develop a multidiscipline structural tailoring method for select composite structures and to demonstrate its application to specific areas. The development of an integrated computer program involves the coupling of three independent computer programs using an excutive module. This module will be the foundation for integrating a structural optimizer, a composites analyzer and a thermal analyzer. With the completion of the executive module, the first step was taken toward the evolution of multidiscipline software in the field of composite mechanics. Through the use of an array of cases involving a variety of objective functions/constraints and thermal-mechanical load conditions, it became evident that simple composite structures can be designed to a combined loads environment.

Acquaviva, Thomas H.

Addressing software security and mitigations in the life cycle

Traditionally, security is viewed as an organizational and Information Technology (IIJ systems function comprising of Firewalls, intrusion detection systems (IDS), system security settings and patches to the operating system (OS) and applications running on it. Until recently, little thought has been given to the importance of security as a formal approach in the software life cycle. The Jet Propulsion Laboratory has approached the problem through the development of an integrated formal Software Security Assessment Instrument (SSAI) with six foci for the software life cycle.

formal methods

Simultaenous Retrieval of Surface Roughness Parameters from Combined Active-Passive SMAP Observations

Soil roughness strongly influences processes like erosion, infiltration, moisture and evaporation of soils as well as growth of agricultural plants. An approach to soil roughness based on active-passive microwave covariation is proposed in order to simultaneously retrieve the vertical RMS height (s) and horizontal correlation length (l) of soil surfaces from simultaneously measured radar and radiometer microwave signatures. The approach is based on a retrieval algorithm for active-passive covariation including the improved Integral Equation Method (I2EM). The algorithm is tested with the global active-passive microwave observations of the SMAP mission. The developed roughness retrieval algorithm shows independence of permittivity for > 10 [-] due to the covariation formalism. Results reveal that s and l can be estimated simultaneously by the proposed approach since surface patterns of non-vegetated areas become evident on global scale. In regions with sandy deserts, like the Sahara or the outback in Australia, determined and confirm rather smooth to semi-rough surface roughness patterns with small vertical RMS heights and corresponding higher horizontal correlation lengths.

correlation length

Dynamic Gate Product and Artifact Generation from System Models

Model Based Systems Engineering (MBSE) is gaining acceptance as a way to formalize systems engineering practice through the use of models. The traditional method of producing and managing a plethora of disjointed documents and presentations ("Power-Point Engineering") has proven both costly and limiting as a means to manage the complex and sophisticated specifications of modern space systems. We have developed a tool and method to produce sophisticated artifacts as views and by-products of integrated models, allowing us to minimize the practice of "Power-Point Engineering" from model-based projects and demonstrate the ability of MBSE to work within and supersede traditional engineering practices. This paper describes how we have created and successfully used model-based document generation techniques to extract paper artifacts from complex SysML and UML models in support of successful project reviews. Use of formal SysML and UML models for architecture and system design enables production of review documents, textual artifacts, and analyses that are consistent with one-another and require virtually no labor-intensive maintenance across small-scale design changes and multiple authors. This effort thus enables approaches that focus more on rigorous engineering work and less on "PowerPoint engineering" and production of paper-based documents or their "office-productivity" file equivalents.

XML

Dynamic Gate Product and Artifact Generation from System Models

Model Based Systems Engineering (MBSE) is gaining acceptance as a way to formalize systems engineering practice through the use of models. The traditional method of producing and managing a plethora of disjointed documents and presentations ("Power-Point Engineering") has proven both costly and limiting as a means to manage the complex and sophisticated specifications of modern space systems. We have developed a tool and method to produce sophisticated artifacts as views and by-products of integrated models, allowing us to minimize the practice of "Power-Point Engineering" from model-based projects and demonstrate the ability of MBSE to work within and supersede traditional engineering practices. This paper describes how we have created and successfully used model-based document generation techniques to extract paper artifacts from complex SysML and UML models in support of successful project reviews. Use of formal SysML and UML models for architecture and system design enables production of review documents, textual artifacts, and analyses that are consistent with one-another and require virtually no labor-intensive maintenance across small-scale design changes and multiple authors. This effort thus enables approaches that focus more on rigorous engineering work and less on "PowerPoint engineering" and production of paper-based documents or their "office-productivity" file equivalents.

engineering paradigm

An analytic method to account for drag in the Vinti satellite theory

A quadrature algorithm is presented which employs analytical expressions for the variations of satellite orbital elements caused by air drag. The Hamiltonian is formally preserved and the Jacobi constants of the motion are advanced with time through the variational equations. The atmospheric density profile is written as a fitted exponential function of the eccentric anomaly, which adheres to tabulated data at all altitudes and simultaneously reduces the variational equations to definite integrals with closed form evaluations, whose limits are in terms of the eccentric anomaly. Results are given for two intense air drag satellites and indicate that the satellite ephemerides produced by this method in conjunction with the Vinti program are of very high accuracy.

Watson, J. S.

A case study for the real-time experimental evaluation of the VIPER microprocessor

An experiment to evaluate the applicability of the Verifiable Integrated Processor for Enhanced Reliability (VIPER) microprocessor to real time control is described. The VIPER microprocessor was invented by the Royal Signals and Radar Establishment (RSRE), U.K., and is an example of the use of formal mathematical methods for developing electronic digital systems with a high degree of assurance on the system design and implementation correctness. The experiment consisted of selecting a control law, writing the control law algorithm for the VIPER processor, and providing real time, dynamic inputs into the processor and monitoring the outputs. The control law selected and coded for the VIPER processor was the yaw damper function of an automatic landing program for a 737 aircraft. The mechanisms for interfacing the VIPER Single Board Computer to the VAX host are described. Results include run time experiences, performance evaluation, and comparison of VIPER and FORTRAN yaw damper algorithm output for accuracy estimation.

Carreno, Victor A.

Assessment of the Orion-SLS Interface Management Process in Achieving the EIA 731.1 Systems Engineering Capability Model Generic Practices Level 3 Criteria

NASA is currently developing the next generation crewed spacecraft and launch vehicle for exploration beyond earth orbit including returning to the Moon and making the transit to Mars. Managing the design integration of major hardware elements of a space transportation system is critical for overcoming both the technical and programmatic challenges in taking a complex system from concept to space operations. An established method of accomplishing this is formal interface management. In this paper we set forth an argument that the interface management process implemented by NASA between the Orion Multi-Purpose Crew Vehicle (MPCV) and the Space Launch System (SLS) achieves the Level 3 tier of the EIA 731.1 System Engineering Capability Model (SECM) for Generic Practices. We describe the relevant NASA systems and associated organizations, and define the EIA SECM Level 3 Generic Practices. We then provide evidence for our compliance with those practices. This evidence includes discussions of: NASA Systems Engineering Interface (SE) Management standard process and best practices; the tailoring of that process for implementation on the Orion to SLS interface; changes made over time to improve the tailored process, and; the opportunities to take the resulting lessons learned and propose improvements to our institutional processes and best practices. We compare this evidence against the practices to form the rationale for the declared SECM maturity level.

Jellicorse, John J.

Directionality effects in the transfer of X-rays from a magnetized atmosphere: Beam pulse shape

A formalism is presented for radiation transfer in two normal polarization modes in finite and semiinfinite plane parallel uniform atmospheres with a magnetic field perpendicular to the surface and arbitrary propagation angles. This method is based on the coupled integral equations of transfer, including emission, absorption, and scattering. Calculations are performed for atmosphere parameters typical of X-ray pulsars. The directionality of the escaping radiation is investigated for several cases, varying the input distributions. Theoretical pencil beam profiles and X-ray pulse shapes are obtained assuming the radiation is emitted from the polar caps of spinning neutron stars. Implications for realistic models of accreting magnetized X-ray sources are briefly discussed.

Meszaros, P.

Modeling Broadband X-Ray Absorption of Massive Star Winds

We present a method for computing the net transition of X-rays emitted by shock-heated plasma distributed throughout a partially optically thick stellar wind from a massive star. We find the transmission by an exact integration of the formal solution, assuming the emitting plasma and absorbing plasma are mixed at a constant mass ratio above some minimum radius, below which there is assumed to be no emission. This model is more realistic than either the slab absorption associated with a corona at the base of the wind or the exospheric approximation that assumes all observed X-rays are emitted without attenuation from above the radius of optical depth unity. Our model is implemented in XSPEC as a pre-calculated table that can be coupled to a user-defined table of the wavelength dependent wind opacity. We provide a default wind opacity model that is more representative of real wind opacities than the commonly used neutral ISM tabulation. Preliminary modeling of Chandra grating data indicates that the X-ray hardness trend of OB stars with spectral subtype cars largely be understood as a wind absorption effect.

Leutenegger, Maurice A.

Recommendations on Evidence and Process for Certification of Learning-enabled Components in Aerospace Systems

This report primarily identifies a collection of relevant and necessary evidence for assurance of machine learnt components (MLCs)—also known as learning-enabled components—integrated into aircraft systems, and gives preliminary suggestions on the elements of a certification process that invoke the identified evidence. The main focus is on feedforward neural networks that are static and trained offline through supervised learning. A brief background on the generic elements of the lifecycle of an MLC is given to contextualize the assurance considerations and, consequently, the evidence that is relevant and necessary to support certification. At the level of an MLC, those considerations relate to: (i) the consistency and correctness of MLC contributions to system functions in the context of a validated functional intent; and (ii) the absence of MLC contributions to aircraft-level failure conditions. At an ML model level, confidence in model and data properties contribute to assurance of the containing MLC, in particular: (a) generalizability and robustness of models, in the presence of inputs not previously seen during training, disturbances to inputs, and unexpected inputs; and (b) valid data, i.e., data that are at least representative, relevant, complete, and accurate. Evidence for the above span the elements of the ML lifecycle, and includes, at a minimum, lifecycle artifacts that pertain to: (1) properties of requirements capturing functional intent, safety constraints, and aspects of the intended use and operating environment; (2) model performance, model complexity and design, and algorithm choice; (3) achievement of required performance at the levels of a trained model during model development, a trained model after model development is complete, and a trained model that is transformed into an executable equivalent; (4) model implementation aspects necessary for transforming a trained model into the executable equivalent; (5) integration of the executable trained model into the containing MLC, and eventually the larger system; and, (6) lastly, the verification and validation (V&V) of each of the above. Such V&V lifecycle artifacts themselves include: aspects of coverage, e.g., of various levels of requirements by the input space of the model and the data; traceability (where applicable); application of formal methods for property specification, analysis, and checking. Examples of evidence generation methods and tools further ground the discussion on what constitutes evidence, and the contribution to assurance during certification. The identified assurance considerations and supporting evidence is not a comprehensive set. Additionally, neither what should be considered as sufficient evidence relative to the assigned criticality of an MLC, nor how criticality ought to be determined and adjusted, have been considered in this report. However, suggestions are made for potential activities of the ML lifecycle that are aimed at providing confidence that an MLC can be relied upon when integrated into its containing (aircraft) system. Those activities are proposed as candidate elements of a certification process for MLCs. The main purpose of this report to inform regulatory guidance and consensus standards that may be used to meet the safety intent of the applicable regulations.

Aviation safety

Operator split methods in the numerical solution of the finite deformation elastoplastic dynamic problem

The spatial formulation of the elastoplastic dynamic problem for finite deformations is considered. A thermodynamic argument leads to an additive decomposition of the spatial rate of deformation tensor and allows an operator split of the evolutionary equations of the problem into elastic and plastic parts. This operator split is taken as the basis for the definition of a global product algorithm. In the context of finite element discretization the product algorithm entails, for every time step, the solution of a nonlinear elastodynamic problem followed by the application of plastic algorithms that operate on the stresses and internal variables at the integration points and bring in the plastic constitutive equations. Suitable plastic algorithms are discussed for the cases of perfect and hardening plasticity and viscoplasticity. The proposed formalism does not depend on any notion of smoothness of the yield surface and is applicable to arbitrary convex elastic regions, with or without corners. The stabiity properties of the global product algorithm are shown to be identical to those of the algorithm used for the integration of the nonlinear elastodynamic problem. Numerical examples illustrate the accuracy of the method.

Pinsky, P. M.

Radiative transfer in spherical atmospheres

A method for defining spherical model atmospheres in radiative/convective and hydrostatic equilibrium is presented. A finite difference form is found for the transfer equation and a matrix operator is developed as the discrete space analog (in curvilinear coordinates) of a formal integral in plane geometry. Pressure is treated as a function of temperature. Flux conservation is maintained within the energy equation, although the correct luminosity transport must be assigned for any given level of the atmosphere. A perturbed integral operator is used in a complete linearization of the transfer and constraint equations. Finally, techniques for generating stable solutions in economical computer time are discussed.

Kalkofen, W.