Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “runtime”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

ATD-2 Benefits Mechanism

NASA has been developing and demonstrating a suite of decision support capabilities for integrated arrival, departure, and surface (IADS) operations in a metroplex environment. The effort is being made in three phases, under NASA’s Airspace Technology Demonstration 2 (ATD-2) sub-project, through a close partnership with the Federal Aviation Administration (FAA), air carriers, airport, and general aviation community. The Phase 1 Baseline IADS capabilities provide enhanced operational efficiency and predictability of flight operations through data exchange and integration, tactical surface metering, and automated coordination of release time of controlled flights for overhead stream insertion. The Phase 2 Fused IADS capabilities include the fusion of strategic and tactical surface metering, Atlanta Center airspace tactical scheduling, Electronic Flight Data (EFD) integration, Terminal Flight Data Manager (TFDM) Terminal Publication (TTP) prototype, and Mobile App for General Aviation (GA) community. In the Phase 2 field evaluation, strategic surface metering provides advance notice of metering and additional stability to the assigned gate holds. The users of the IADS system in Phases 1 and 2 include the personnel at Charlotte Douglas International Airport (CLT) air traffic control tower, American Airlines ramp tower, CLT terminal radar approach control (TRACON), and Washington and Atlanta Center. This document describes the ATD-2 benefits mechanism used to assess the Phases 1 and 2 IADS capabilities and field evaluation conducted at CLT since September 2017. The ATD-2 benefits mechanism mainly consists of surface metering and overhead stream insertion. This document provides detailed calculation methods of major benefit metrics, such as fuel savings, gas emissions savings, and engine runtime reduction, which can be obtained through surface metering, gate hold of Approval Request (APREQ) flights prior to pushback, and the renegotiation of release time while taxiing. As of April 30, 2020, it is estimated that 5,097,173 pounds of fuel savings and 15,699,292 pounds of CO2 emission reduction have been achieved so far, with a reduction of 3,831 hours in total engine runtime. The amount of CO2 savings is estimated to be equivalent to planting 116,739 urban trees. The pre- and post-metering comparison results using FAA’s Aviation System Performance Metrics (ASPM) data have also shown that the surface metering had no negative impact on the on-time arrival performance of both outbound and inbound flights at CLT.

ATD-2↗

A Flight Rule Checker for the LADEE Lunar Spacecraft

As part of the design of a space mission, an important part is the design of so-called flight rules. Flight rules express constraints on various parts and processes of the mission, that if followed, will reduce the risk of failure. One such set of flight rules constrain the format of command sequences regularly (e.g. daily) sent to the spacecraft to con-trol its next near term behavior. We present a high-level view of the automated flight rule checker FRC for checking command sequences sent to NASA’s LADEE Lunar mission spacecraft, used throughout its entire mission. A command sequence is in this case essentially a program (a sequence of commands) with no loops or conditionals, and it can there-fore be verified with a trace analysis tool. FRC is implemented using the TraceContract runtime verification tool, an internal Scala DSL for checking event sequences against “formal specifications”. The paper illustrates this untraditional use of runtime verification in a real con-text, with strong demands on the expressiveness and flexibility of the specification language, illustrating the advantages of an internal DSL.

LADEE↗

Refining the Safety - Liveness Classification of Temporal Properties According to Monitorability

Runtime verification is the topic of analyzing execution traces using formal techniques. It includes monitoring the execution of a system against temporal properties, commonly to detect violations. Not every temporal property is fully monitorable however: in some cases, the correctness of the execution does not depend on any finite prefix. We study the connection between monitorability and Lamport’s classification of properties to safety and liveness and their dual classes.We refine the definition of monitorability and provide algorithms to check which verdicts can be expected, a priori and during runtime verification.

Peled, Doron↗

Predicting Unreinforced Fabric Mechanical Behavior with Recurrent Neural Networks

Unreinforced woven fabrics are widely employed in various high-performance applications, including parachute deployment systems, airbags, and ballistic armor. The analysis of such materials is inherently complex due to the multiscale structure of these materials, and the dependence of macroscale behavior on changes that occur at lower scales. Previously, NASA’s Multiscale Analysis Tool (NASMAT) showed its capability in predicting unreinforced fabric behavior at the macroscale by capturing finite rotations that occur at the mesoscale. Though effective, the tool can face high computational cost for large, complex problems, motivating the need for the development of a surrogate model that can capture the same behavior. A recurrent neural network (RNN) was developed and trained on virtual NASMAT data to mimic the physics-based solutions while improving the computational runtime. The architecture of the RNN to best simulate the fabric behavior was carefully crafted based on heuristic knowledge of predicting physics-based temporal data, manual hyperparameter case studies, and Hyperband optimization.. The resultant model was able to predict a variety of stress-strain curves for fabrics with different mesoscale geometries, and was further validated by comparing to experimental data for the K706 style Kevlar plain-weave fabric, demonstrating the ability of the model to effectively capture the geometric changes in the fabric without explicitly calculating them, as is done in NASMAT. Furthermore, the tool showed its ability to improve on the runtime by a factor of 10 for fabric solutions compared to the multiscale tool, which would further enable the simulation of complex loading scenarios on unreinforced fabrics.

Fabric↗

A Flight Rule Checker for the LADEE Lunar Spacecraft

As part of the design of a space mission, an important part is the design of so-called flight rules. Flight rules express constraints on various parts and processes of the mission, that if followed, will reduce the risk of failure. One such set of flight rules constrain the format of command sequences regularly (e.g. daily) sent to the spacecraft to con- trol its next near term behavior. We present a high-level view of the automated flight rule checker Frc for checking command sequences sent to NASA’s LADEE Lunar mission spacecraft, used throughout its entire mission. A command sequence is in this case essentially a program (a sequence of commands) with no loops or conditionals, and it can there- fore be verified with a trace analysis tool. Frc is implemented using the TraceContract runtime verification tool, an internal Scala DSL for checking event sequences against “formal specifications”. The paper illustrates this untraditional use of runtime verification in a real con- text, with strong demands on the expressiveness and flexibility of the specification language, illustrating the advantages of an internal DSL.

Kurklu, Elif↗

Estimating groundwater use and demand in arid Kenya through assimilation of satellite data and in-situ sensors with machine learning toward drought early action

Groundwater is an important source of water for people, livestock, and agriculture during drought in the Horn of Africa. In this work, areas of high groundwater use and demand in drought-prone Kenya were identified and forecasted prior to the dry season. Estimates of groundwater use were extended from a sentinel network of 69 in-situ sensored mechanical boreholes to the region with satellite data and a machine learning model. The sensors contributed 756 site-month observations from June 2017 to September 2021 for model building and validation at a density of approximately one sensor per 3700 sq.km. An ensemble of 19 parameterized algorithms was informed by features including satellite-derived precipitation, surface water availability, vegetation indices, hydrologic land surface modeling, and site characteristics to dichotomize high groundwater pump utilization. Three operational definitions of high demand on groundwater infrastructure were considered: 1) mechanical runtime of pumps greater than a quarter of a day (6+ hr) and daily per capita volume extractions indicative of 2) domestic water needs (35+ L), and 3) intermediate needs including livestock (75+ L). Gridded interpolation of localized groundwater use and demand was provided from 2017 to 2020 and forecasted for the 2021 dry season, June–September 2021. Cross-validated skill for contemporary estimates of daily pump runtime and daily volume extraction to meet domestic and intermediate water needs was 68%, 69%, and 75%, respectively. Forecasts were externally validated with an accuracy of at least 56%, 70%, or 72% for each groundwater use definition. The groundwater maps are accessible to stakeholders including the Kenya National Drought Management Authority (NDMA) and the Famine Early Warning Systems Network (FEWS NET). These maps represent the first operational spatially-explicit sub-seasonal to seasonal (S2S) estimates of groundwater use and demand in the literature. Knowledge of historical and forecasted groundwater use is anticipated to improve decision-making and resource allocation for a range of early warning early action applications.

Katie Fankhauser↗

Components Refurbishment and Chemical Analysis Facility, Hot Spot 1 SWMU #041 Year 3 Annual Performance Monitoring Report Kennedy Space Center, Florida

This Year 3 Annual Performance Monitoring Report (PMR) presents the operations, maintenance, and monitoring activities for the Hydraulic Containment System (HCS) Interim Measure (IM) at the Components Refurbishment and Chemical Analysis (CRCA) facility located at John F. Kennedy Space Center (KSC), Florida. The primary objective of the HCS is to attain hydraulic control of the dissolved-phase chlorinated volatile organic compound (CVOC) plume, with the secondary objective to reduce concentrations of CVOCs in the high-concentration plume to support transition to monitored natural attenuation (MNA). CRCA has been designated Solid Waste Management Unit 041 under the KSC Resource Conservation and Recovery Act Corrective Action Program. The timeframe for activities documented in this Year 3 PMR extends from September 2021 through October 2022. Baseline sampling activities were completed in June 2019, and full-scale startup of the HCS IM was completed in July-August 2019. The operational runtime of the HCS for the Year 3 reporting period was approximately 91%, with the majority of downtime attributed to system maintenance and repair. This is generally consistent with Year 1 and Year 2 runtimes of 85% and 92%, respectively. To help reduce downtime, an anti-scaling amendment, Redux 390, has been used to reduce scaling and help maintain system design parameters. Over nine million gallons of groundwater were treated during Year 3 of HCS operations, and concentrations of the site’s contaminants of concern (trans-1,2-dichloroethene and vinyl chloride) have been reduced by over 97%. This PMR describes the activities that were performed during Year 3 to operate and monitor the HCS IM, which includes three extraction wells, seven injection wells, and conveyance piping to a modular structure containing the control panel and an air stripper. Influent and effluent sampling results from the air stripper show that the system is operating as designed and is reducing concentrations of contaminants of concern to below detection limits. In addition to HCS operation, this PMR also discusses performance monitoring that has been implemented to assess progress of the HCS IM and overall plume conditions through scheduled groundwater (quarterly and semi-annual) and sub-slab soil gas (quarterly) sampling and analysis. Two ambient air samples were also collected on a quarterly basis in the vicinity of the modular structure and the paved driveway east of the Solvent Reclamation Area during routine operation and maintenance (O&M) activities to ensure safe breathing zone air quality for on-site personnel. All sub-slab soil gas and ambient air sampling conducted during the Year 3 operational period showed results below applicable regulatory air screening limits. Predictions made during the Year 2 groundwater model updates were in close correlation to post Year 3 plume conditions. Therefore, it can be assumed that the projected path remains valid for transition to MNA in one to two years of continuous HCS operation. The contents of this Year 3 PMR were presented during the February 2023 KSC Remediation Team meeting, where Team consensus was reached on several items including continued O&M of the HCS, and continued monitoring of groundwater, ambient air, and sub-slab soil gas. Replacement of MW0019 and VMP04 was also recommended, as well as additional direct-push technology sampling to further delineate the downgradient plume and confirm overall site-wide low-concentration plume boundaries. Sampling for per- and polyfluoroalkyl substances at CRCA is ongoing and will be submitted under separate cover.

K. Alex Murphy↗

Trustworthy Autonomy for Gateway Vehicle System Manager

The Vehicle System Manager (VSM) is the highest-level software control system in the Gateway hierarchical Autonomous System Management Architecture. The VSM provides four function categories: Mission Management and Timeline Execution, Resource Management, Fault Management, Vehicle Control and Operation. VSM provides various levels of automation ranging from fully autonomous operations with no flight crew and minimal ground monitoring to advisory automation when Gateway is crewed and has full ground monitoring. Trustworthiness is achieved via verified specification, comprehensive development verification, and real-time verification using assume-guarantee contracts. Development verification includes semantic verification of the data model via peer review and testing and assume-guarantee contracts implemented using the PlusCal/TLA+ environment. VSM also uses runtime assume-guarantee contracts, implemented in R2U2 via a runtime monitor that feeds the necessary telemetry data to R2U2 and which receives and responds to the R2U2 verdict stream. The full lifecycle verification approach and use of assume-guarantee contracts provides increased trustworthiness to VSM. Preliminary results provide encouragement that VSM can be both autonomous and trustworthy.

Assume-guarantee contracts↗

NASA Orbital Debris Engineering Model ORDEM 3.2 – Software User Guide

This National Aeronautics and Space Administration (NASA) Orbital Debris Engineering Model (ORDEM) 3.2 Software User Guide accompanies delivery of the latest upgraded version of the model, ORDEM 3.2. The user guide also provides a top-level program description and a list of capabilities. It includes descriptions of runtime error and information codes, input/output file formats, runtimes for different orbit configurations, and how to use uncertainty files. ORDEM 3.2 supersedes the previous NASA Orbital Debris Program Office (ODPO) models – ORDEM 3.0 (Stansbery, et al. 2014) and ORDEM2000 (Liou, et al. 2002). The availability of new sensor and in situ data, re-analysis of older data, and development of new analytical techniques has enabled the construction of this more comprehensive and sophisticated model. An upgraded graphical user interface (GUI) is integrated with the software. This upgraded GUI uses project-oriented organization and provides the user with graphical representations of numerous output data products. For example, these range from the conventional flux vs. average debris size (or altitude bin) for chosen analysis orbits (or views) to the more complex color-contoured, two-dimensional (2-D) directional flux diagrams in local spacecraft elevation and azimuth. The current model, ORDEM 3.2, supports spacecraft as well as telescope/radar project assessments. ORDEM 3.2 contains updated debris populations covering low Earth orbit (LEO, up to 2000 km altitude) to geosynchronous orbit (GEO, up to 40,000 km altitude) and can assess debris calculations up to year 2050, extending coverage past the previous limit of 2035 in ORDEM 3.0. Although populations differ from its predecessor, ORDEM 3.2 is functionally the same as ORDEM 3.0 and can support ORDEM 3.0 projects through backward compatibility.

Andrew Vavrin↗

Launch Complex 39B, SWMU 009, 2023 Performance Monitoring and Air Sparge Expansion Construction Completion Report, Kennedy Space Center, Florida

The 2023 Performance Monitoring and Construction Completion Report (PM-CCR) presents the findings, observations, and results for Air Sparging (AS) operations and expansion activities, as well as sitewide groundwater monitoring for Launch Complex 39B (LC39B), Solid Waste Management Unit (SWMU) 009, at Kennedy Space Center (KSC), Florida. The reporting period for activities covered under this PM-CCR is from January 1, 2023, to December 31, 2023. At LC39B, AS operations began in 2017 in the area west of the launch pad, in the liquid oxygen (LOX) tank area located northwest of the launch pad, and in an area outside of the perimeter fence to protect nearby Outstanding Florida Waters (OFW). The LC39B AS system was installed with 279 AS wells to depths ranging from 23 to 60 feet below land surface (bls), including the sump, correlating to top of screen depths ranging from 20 to 57 feet bls. In December 2022, a total of 22 AS wells were abandoned to support launch pad crane operations, and in November 2023, the system was expanded with five additional AS wells installed to 13 or 17 feet bls near the LOX tank. The remedial objective of the LC39B AS Interim Measure (IM) is to actively decrease concentrations of contaminants of concern (COCs) in groundwater, specifically trichloroethene (TCE), cis-1,2-Dichloroethene (cDCE), and vinyl chloride (VC), to less than their respective Natural Attenuation Default Concentrations (NADCs), so LC39B can transition into a Long-Term Monitoring (LTM) program. This PM-CCR presents the following information for LC39B: • AS system operations and maintenance (O&M) (Year 7 of operation) from January 2023 to December 2023, to include AS trailer relocation in March 2023 and subsequent replacement and re-start in June 2023. • Construction completion details for AS system expansion, which included installation of five new AS wells and one new monitoring well in November 2023. As part of expansion activities, soil samples were also collected for petroleum analysis; no exceedances were identified, and no further investigation for petroleum is warranted. • Performance monitoring results for groundwater sampling events conducted in May/June 2023 (30 wells) and November 2023 (31 wells) in the AS IM area and in the Low Concentration Plume (LCP) areas located north and east of the launch pad for volatile organic compound (VOC) analysis. • Sampling results for one monitoring well, LOX-IW0012S, which is sampled for aluminum on an annual basis (May/June 2023). This well was resampled in November 2023 for both total and dissolved aluminum. Due to a communication error with the laboratory, the May/June 2023 sample was analyzed for total aluminum only. • Groundwater sampling results for per- and polyfluoroalkyl substances (PFAS) collected from seven monitoring wells during the May/June 2023 event to further investigate the Former Sewage Treatment Plant #6 and Percolation Pond area, west of the launch pad. O&M and performance monitoring results show that the AS system at LC39B is operating as designed and meeting performance criteria. Overall runtime was 45 percent (%) during the reporting period (January to December), but the operational runtime was 78% during the timeframe when the system could run (June to December). The most significant downtime contributor was post-launch crane operations following the Artemis launch on November 16, 2022, which lasted until June 2023. During that timeframe, the AS trailer at LC39B was relocated to another KSC remediation site (Wilson Corners) and was subsequently replaced with the AS trailer from the Paint & Oil Locker (POL) remediation site at KSC to resume AS system operations. Performance monitoring results in the AS IM and LCP areas continue to show reduction in COC concentrations over time when compared to baseline levels. In 2023, only one monitoring well (MW0048) detected a COC exceeding its NADC (VC at 740 micrograms per liter [µg/L]), which marks the baseline result for this new well installed during system expansion. Across the rest of the site, VC concentrations have declined or remained stable during the 2023 sampling events. Excluding MW0048, the highest VC result in 2023 was during the May/June sampling event with a concentration of 63 µg/L at MW0032, which is located near MW0048 and the AS expansion area by the LOX tank. TCE was detected in select monitoring wells in the IM area in 2023, but only two locations exceeded the State of Florida Groundwater Cleanup Target Level (GCTL): MW0032 (21 µg/L in May/June 2023 and 9.1 µg/L in November 2023) and MW0036 (5.0 µg/L in November 2023). MW0036 is also located near the LOX tank, on the north side, where the AS system is still operational (Zone Z4). cDCE and trans-1,2-dichloroethene concentrations were less than laboratory method detection limits or their respective GCTLs in all wells sampled in 2023. Near the OFW located northwest of the launch complex, all COC concentrations were less than laboratory method detection limits from monitoring wells (MW0039, MW0040, and LOXTA0002S) sampled in 2023. Aluminum results from LOX-IW0012S, which has been sampled routinely since 2006, detected a total aluminum concentration of 3,900 µg/L during the May/June 2023 sampling event. Results from the November 2023 event detected 5,700 µg/L for total aluminum and 5,500 µg/L for dissolved aluminum. These concentrations slightly decreased from the previous year but remain relatively consistent with historical detections. Aluminum will continue to be sampled on an annual basis at this well as results still exceed the GCTL of 200 µg/L and the Upper Limit of the KSC Background Concentration of 280 µg/L. PFAS results detected nine different PFAS compounds (out of 32 analyzed) from seven wells sampled. Two PFAS compounds, perfluorooctanesulfonic acid (PFOS) and perfluorooctanoic acid (PFOA), currently have FDEP Provisional GCTLs of 70 nanograms per liter (ng/L). All seven samples collected resulted in concentrations less than the FDEP Provisional GCTLs for both PFAS compounds; no exceedances were observed. PFOS and PFOA also have assigned United States Environmental Protection Agency (USEPA) Maximum Contaminant Levels (MCLs) of 4 nanograms per liter (ng/L). None of the PFOS results exceeded the USEPA MCLs. PFOA was detected in two samples above the USEPA MCL at concentrations of 5.8 ng/L (ECS-IW0009I) and 5.5 ng/L (ECS-IW0009S). Three other PFAS compounds, perfluorohexanesulfonic acid (PFHxS), perfluoro-n-nonanoic acid (PFNA), and hexafluoropropylene oxide dimer acid (GenX), currently have USEPA MCLs of 10 ng/L. PFHxS, PFNA, and GenX were not detected at concentrations greater than their respective USEPA MCLs in any of the seven wells. PFAS compounds without FDEP Provisional GCTLs or USEPA MCLs were screened against USEPA RSLs. No other detections exceeded their respective USEPA RSLs. Additional PFAS sampling will be conducted as part of a future PFAS Site Assessment. Based on O&M activities and performance monitoring, the following is recommended for LC39B: • Continue with Year 8 AS system operation within Zone Z4, which includes the AS expansion area. Zone Z3, which has been off since 2018, should remain off as no rebound has been observed. Zones Z1 and Z2, which were turned off at the end of 2022, will remain shut down as monitoring well results have consistently been below GCTLs or have low-level detections with stable or decreasing trends (Meeting Minute 2402-M10, Decision 2402-D30). • Continue with performance monitoring in 2024 with the same monitoring well network as 2023, except with the addition of MW0048 in both semi-annual events. Baseline concentrations for this well were collected during the November 2023 performance monitoring event. Semi-annual sampling should be planned for the May 2024 and November 2024 timeframes (Meeting Minute 2402-M10, Decision 2402-D31). • Continue sampling monitoring well, LOX-IW0012S, for aluminum (total and dissolved) on an annual basis in May 2024. It is also recommended to re-develop this well prior to the next sampling event (Meeting Minute 2402-M10, Decision 2402-D32). The above recommendations for LC39B were presented at the February 2024 KSCRT Meeting, with Team consensus reached on the path forward. The contents of this PM-CCR were also presented at this meeting.

Deborah M Wilson↗

Aspect-Oriented Monitoring of C Programs

The paper presents current work on extending ASPECTC with state machines, resulting in a framework for aspect-oriented monitoring of C programs. Such a framework can be used for testing purposes, or it can be part of a fault protection strategy. The long term goal is to explore the synergy between the fields of runtime verification, focused on program monitoring, and aspect-oriented programming, focused on more general program development issues. The work is inspired by the observation that most work in this direction has been done for JAVA, partly due to the lack of easily accessible extensible compiler frameworks for C. The work is performed using the SILVER extensible attribute grammar compiler framework, in which C has been defined as a host language. Our work consists of extending C with ASPECTC, and subsequently to extend ASPECTC with state machines.

runtime verifications↗

Data Automata in Scala

The field of runtime verification has during the last decade seen a multitude of systems for monitoring event sequences (traces) emitted by a running system. The objective is to ensure correctness of a system by checking its execution traces against formal specifications representing requirements. A special challenge is data parameterized events, where monitors have to keep track of the combination of control states as well as data constraints, relating events and the data they carry across time points. This poses a challenge wrt. efficiency of monitors, as well as expressiveness of logics. Data automata is a form of automata where states are parameterized with data, supporting monitoring of data parameterized events. We describe the full details of a very simple API in the Scala programming language, an internal DSL (Domain-Specific Language), implementing data automata. The small implementation suggests a design pattern. Data automata allow transition conditions to refer to other states than the source state, and allow target states of transitions to be inlined, offering a temporal logic flavored notation. An embedding of a logic in a high-level language like Scala in addition allows monitors to be programmed using all of Scala's language constructs, offering the full flexibility of a programming language. The framework is demonstrated on an XML processing scenario previously addressed in related work.

runtime verification↗

Comprehension of Spacecraft Telemetry Using Hierarchical Specifications of Behavior

A key challenge in operating remote spacecraft is that ground operators must rely on the limited visibility available through spacecraft telemetry in order to assess spacecraft health and operational status. We describe a tool for processing spacecraft telemetry that allows ground operators to impose structure on received telemetry in order to achieve a better comprehension of system state. A key element of our approach is the design of a domain-specific language that allows operators to express models of expected system behavior using partial specifications. The language allows behavior specifications with data fields, similar to other recent runtime verification systems. What is notable about our approach is the ability to develop hierarchical specifications of behavior. The language is implemented as an internal DSL in the Scala programming language that synthesizes rules from patterns of specification behavior. The rules are automatically applied to received telemetry and the inferred behaviors are available to ground operators using a visualization interface that makes it easier to understand and track spacecraft state. We describe initial results from applying our tool to telemetry received from the Curiosity rover currently roving the surface of Mars, where the visualizations are being used to trend subsystem behaviors, in order to identify potential problems before they happen. However, the technology is completely general and can be applied to any system that generates telemetry such as event logs.

Runtime monitoring↗

R2U2 in Space: System and Software Health Management for Small Satellites

In order for small but complex systems like rovers, SmallSats, or Unmanned Aircraft (UAS) to operate autonomously, they must have a real-time solution for assessing their own system health. System and Software Health Management (SHM) enables better detection of faulty sensors and software problems, and enables better fault management including mitigation of unpredicted fault scenarios in the absence of a human on-board. In recent work, we have developed a Responsive, Realizable, Unobtrusive Unit (R2U2) for on-board SHM of autonomous UAS and demonstrated its ability to detect faults during flight time. These faults, from sensor failures, to software problems, to malicious security attacks, can present as transient temporal faults that even humans are challenged to find. An R2U2 congfiuration is a modular combination of multiple types of temporal logic runtime observers with fault-specic Bayesian Nets and sensor filters. R2U2 reasons about both on-board hardware and software components; R2U2 itself can be instantiated as an independent FPGA (Field-Programmable Gate Array)-based conguration or as a software component running independently from other software on-board. Small satellites, such as CubeSats, also require on-board SHM and failure mitigation, as limited telemetry bandwidth does not allow the transmission of the entire system state for ground-based health management. However, the autonomous operation of satellites brings a set of challenges different from UAS, including the effects of radiation on non-rad-hard, low-cost components, and the harsher environment of space. We surmise that a new extension of R2U2 could be adapted to help better detect, for example, radiation errors in cheaper COTS (Commercial Off the Shelf) (not rad-hard) components often used in small space systems. Since small satellites often operate in coordination, we will also examine new ways of distributed monitoring of their communication and cooperation and real-time detection of off-nominal situations utilizing multiple satellites. This talk will discuss preliminary work and ideas for building on terrestrial success of system and software health management for the harsher, and differently challenging, environment of space.

Runtime Verification & Validation↗

Using FRET to Create, Analyze and Monitor Requirements for a Lift Plus Cruise Case Study

In this technical report we provide information on the use of the NASA Formal RequirementsElicitation Tool (FRET) to create requirements for a Lift Plus Cruise (LPC) aircraft case study. Furthermore, we provide details on using FRET to translate these requirements into an appropriate format for the Copilot tool, enabling their usage to perform runtime verification on a synthesized LPC system.

Formal Requirements Elicitation Tool↗

HAL/S-FC compiler system functional specification

The functional requirements to be met by the HAL/S-FC compiler, and the hardware and software compatibilities between the compiler system and the environment in which it operates are defined. Associated runtime facilities and the interface with the Software Development Laboratory are specified. The construction of the HAL/S-FC system as functionally separate units and the interfaces between those units is described. An overview of the system's capabilities is presented and the hardware/operating system requirements are specified. The computer-dependent aspects of the HAL/S-FC are also specified. Compiler directives are included.

Source record↗

TENEX SAIL

SAIL, a high level ALGOL language for the PDP-10, is extended to operate under the TENEX time sharing system without executing DEC system calls. A large set of TENEX oriented runtime routines are added to allow complete access to TENEX. The emphasis is on compatibility of programs across time sharing systems and integrity of the language.

Smith, R.↗

Earth Resources Laboratory Applications Software (ELAS)

Implementation of the Earth Resources Laboratory applications software (ELAS) system is described. A Data General Eclipse model S/230 minicomputer is employed for image processing of LANDSAT data. A 16 bit word is used, and the smaller addressability necessitates reducing some of the array sizes. All INTEGER*4 variables were changed to REAL. Interfacing the ELAS software to Data General's FORTRAN callable runtime routines required rewriting the input/output routines and the subroutines that bring in the various overlays. Overlay relinking is required when a change is made in resident routines. The ELAS system and its user documentation is evaluated.

Balcerek, T. W.↗