Engineering PapersSearch

SEARCH · Engineering Papers

Results for “Model based development”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Testing Strategies for Model-Based Development

This report presents an approach for testing artifacts generated in a model-based development process. This approach divides the traditional testing process into two parts: requirements-based testing (validation testing) which determines whether the model implements the high-level requirements and model-based testing (conformance testing) which determines whether the code generated from a model is behaviorally equivalent to the model. The goals of the two processes differ significantly and this report explores suitable testing metrics and automation strategies for each. To support requirements-based testing, we define novel objective requirements coverage metrics similar to existing specification and code coverage metrics. For model-based testing, we briefly describe automation strategies and examine the fault-finding capability of different structural coverage metrics using tests automatically generated from the model.

Heimdahl, Mats P. E.

Is Model-Based Development a Favorable Approach for Complex and Safety-Critical Computer Systems on Commercial Aircraft?

A system is safety-critical if its failure can endanger human life or cause significant damage to property or the environment. State-of-the-art computer systems on commercial aircraft are highly complex, software-intensive, functionally integrated, and network-centric systems of systems. Ensuring that such systems are safe and comply with existing safety regulations is costly and time-consuming as the level of rigor in the development process, especially the validation and verification activities, is determined by considerations of system complexity and safety criticality. A significant degree of care and deep insight into the operational principles of these systems is required to ensure adequate coverage of all design implications relevant to system safety. Model-based development methodologies, methods, tools, and techniques facilitate collaboration and enable the use of common design artifacts among groups dealing with different aspects of the development of a system. This paper examines the application of model-based development to complex and safety-critical aircraft computer systems. Benefits and detriments are identified and an overall assessment of the approach is given.

Torres-Pomales, Wilfredo

Orion GN and C Model Based Development: Experience and Lessons Learned

The Orion Guidance Navigation and Control (GN&C) team is charged with developing GN&C algorithms for the Exploration Flight Test One (EFT-1) vehicle. The GN&C team is a joint team consisting primarily of Prime Contractor (Lockheed Martin) and NASA personnel and contractors. Early in the GN&C development cycle the team selected MATLAB/Simulink as the tool for developing GN&C algorithms and Mathworks autocode tools as the means for converting GN&C algorithms to flight software (FSW). This paper provides an assessment of the successes and problems encountered by the GN&C team from the perspective of Orion GN&C developers, integrators, FSW engineers and management. The Orion GN&C approach to graphical development, including simulation tools, standards development and autocode approaches are scored for the main activities that the team has completed through the development phases of the program.

Jackson, Mark C.

A Spectrum of IV and V Modeling Techniques

The aerospace industry in general and NASA in particular is using more (semi-formal) model-based software development. Model-based development produces a collection of artifacts, for example, state diagrams, module diagrams (such as class diagrams), control-block diagrams, etc. These artifacts may than be used as a basis for auto code generation for production use. Therefore, these models must be properly evaluated in the IV and V process. IV and V practitioners know how assess standard procedural systems. But what can we du about IV and V of model-based systems? The goal of the work outlined in this proposal is to use cost effective automated techniques to the largest extent possible during the IV and V process. Our working hypotheses are: 1. There exists a range of validation techniques that can assess models built using a range of modeling techniques of increasing cost and complexity. Specifically, we hypotesize that the "cheaper" techniques can find faults cheaply and early in a project. These early results are then used to predict if this is a problem system and if a more elaborate and expensive IV and V effort is justified. 2. There exists a set of migration procedures that let us seamlessly move from simple models using cheaper techniques into more elaborate models suitable for a more expensive and detailed analysis. 3. We further hypothesize that this migration process is much cheaper than simply remodeling the system under investigation from scratch when moving to models needed for the more detailed and expensive IV and V assessments.

Heimdahl, Mats

Assessing Requirements Quality through Requirements Coverage

In model-based development, the development effort is centered around a formal description of the proposed software system the model. This model is derived from some high-level requirements describing the expected behavior of the software. For validation and verification purposes, this model can then be subjected to various types of analysis, for example, completeness and consistency analysis [6], model checking [3], theorem proving [1], and test-case generation [4, 7]. This development paradigm is making rapid inroads in certain industries, e.g., automotive, avionics, space applications, and medical technology. This shift towards model-based development naturally leads to changes in the verification and validation (V&V) process. The model validation problem determining that the model accurately captures the customer's high-level requirements has received little attention and the sufficiency of the validation activities has been largely determined through ad-hoc methods. Since the model serves as the central artifact, its correctness with respect to the users needs is absolutely crucial. In our investigation, we attempt to answer the following two questions with respect to validation (1) Are the requirements sufficiently defined for the system? and (2) How well does the model implement the behaviors specified by the requirements? The second question can be addressed using formal verification. Nevertheless, the size and complexity of many industrial systems make formal verification infeasible even if we have a formal model and formalized requirements. Thus, presently, there is no objective way of answering these two questions. To this end, we propose an approach based on testing that, when given a set of formal requirements, explores the relationship between requirements-based structural test-adequacy coverage and model-based structural test-adequacy coverage. The proposed technique uses requirements coverage metrics defined in [9] on formal high-level software requirements and existing model coverage metrics such as the Modified Condition and Decision Coverage (MC/DC) used when testing highly critical software in the avionics industry [8]. Our work is related to Chockler et al. [2], but we base our work on traditional testing techniques as opposed to verification techniques.

Rajan, Ajitha

Architectural Modeling and Analysis for Safety Engineering

Model-based development tools are increasingly being used for system-level development of safety-critical systems. Architectural and behavioral models provide important information that can be leveraged to improve the system safety analysis process. Model-based design artifacts produced in early stage development activities can be used to perform system safety analysis, reducing costs and providing accurate results throughout the system life-cycle. In this report we describe an extension to the Architecture Analysis and Design Language (AADL) that supports modeling of system behavior under failure conditions. This Safety Annex enables the independent modeling of component failures and allows safety engineers to weave various types of fault behavior into the nominal system model. The accompanying tool support uses model checking to propagate errors from their source to their effect on safety properties without the need to add separate propagation specifications. The tool also captures all minimal set of fault combinations that can cause violation of the safety properties, that can be compared to qualitative and quantitative objectives as part of the safety assessment process. We describe the Safety Annex, illustrate its use with a representative example, and discuss and demonstrate the tool support enabling an analyst to investigate the system behavior under failure conditions.

FTA

Experimental Setup and Learning-Based AI Model for Developing Accurate PV Inverter Models

The integration of power electronics-based interfaces presents challenges due to the absence of detailed models and the high computational complexity. Generic models used in system studies lack accuracy in capturing converter dynamics. This paper proposes a data-driven approach developed from experimental setup data. This approach enhances accuracy in photovoltaic inverter modeling. We used two types of PV inverters in the experiment. The recorded experimental data undergo processing through a machine learning model. Results from the model trained through machine learning is also presented.

artificial intelligence

Observer-Based Magnetic Bearing Controller Developed for Aerospace Flywheels

A prototype of a versatile, observer-based magnetic bearing controller for aerospace flywheels was successfully developed and demonstrated on a magnetic bearing test rig (see the photograph) and an actual flywheel module. The objective of this development included a fast, yet low risk, control development process, and a robust, high-performance controller for a large variety of flywheels. This required a good system model, an efficient development procedure, and a model-based controller that addressed the key problems associated with flywheel and bearing imbalance, sensor error, and vibration. The model used in this control development and tuning procedure included the flexible rotor dynamics and motor-induced vibrations. Such a model was essential for low-risk scheduling of speed-dependent control parameters and for reliable evaluation of novel control strategies. The successfully tested control prototype utilized an extended Kalman filter to estimate the true rotor principal-axis motion from the raw sensor position feedback. For control refinement, the extended Kalman filter also estimated and eliminated the combined effects of mass-imbalance and sensor runouts from the input data. A key advantage of the design based on the extended Kalman filter is its ability to accurately estimate both the rotor's principal-axis position and gyroscopic rates with the least amount of phase lag. This is important for control parameter scheduling to dampen the gyroscopic motions. Because of large uncertainties in the magnetic bearing and imbalance characteristics, this state-estimation scheme alone is insufficient for containing the rotor motion within the desired 1-mil excursion radius. A nonlinear gain adjustment based on an estimation of the principal-axis orbit size was needed to provide a coarse (nonoptimal), but robust, control of the orbit growth. Control current minimization was achieved with a (steepest gradient) search of synchronous errors in the principal-axis position input data. Actual flywheel tests of this observer-based controller (developed entirely in-house) at the NASA Glenn Research Center showed that the model correctly predicted the rotor orbit growth as a function of rotational speed, and it demonstrated the capability of gain adjustments to arrest this growth. Data from these tests on an actual flywheel module spun to 26,000 rpm proved that the controller was able to contain the shaft motion to within much less than 0.5 mils of radial excursion with axis currents less than 300 mA in root-mean-square estimate. The test speed range was limited because of thermal expansion concerns for this particular flywheel unit, not because of any deficiency in the controller. Simulations for this unit indicated that the controller should be robust up to its top operating speed of 60,000 rpm. Aside from these important achievements, and most significantly, it took less than 1 week to adapt this controller from the simple test rig to the actual flywheel and to demonstrate full five-axis levitation and control. This demonstration showed that both the controller and the model-based development and tuning framework are easily adaptable to a wide range of rotors and bearing configurations and, hence, are capable of reducing design risks and costs for many future flywheel technology developments.

Le, Dzu K.

Modeling Guidelines for Code Generation in the Railway Signaling Context

Modeling guidelines constitute one of the fundamental cornerstones for Model Based Development. Their relevance is essential when dealing with code generation in the safety-critical domain. This article presents the experience of a railway signaling systems manufacturer on this issue. Introduction of Model-Based Development (MBD) and code generation in the industrial safety-critical sector created a crucial paradigm shift in the development process of dependable systems. While traditional software development focuses on the code, with MBD practices the focus shifts to model abstractions. The change has fundamental implications for safety-critical systems, which still need to guarantee a high degree of confidence also at code level. Usage of the Simulink/Stateflow platform for modeling, which is a de facto standard in control software development, does not ensure by itself production of high-quality dependable code. This issue has been addressed by companies through the definition of modeling rules imposing restrictions on the usage of design tools components, in order to enable production of qualified code. The MAAB Control Algorithm Modeling Guidelines (MathWorks Automotive Advisory Board)[3] is a well established set of publicly available rules for modeling with Simulink/Stateflow. This set of recommendations has been developed by a group of OEMs and suppliers of the automotive sector with the objective of enforcing and easing the usage of the MathWorks tools within the automotive industry. The guidelines have been published in 2001 and afterwords revisited in 2007 in order to integrate some additional rules developed by the Japanese division of MAAB [5]. The scope of the current edition of the guidelines ranges from model maintainability and readability to code generation issues. The rules are conceived as a reference baseline and therefore they need to be tailored to comply with the characteristics of each industrial context. Customization of these recommendations has been performed for the automotive control systems domain in order to enforce code generation [7]. The MAAB guidelines have been found profitable also in the aerospace/avionics sector [1] and they have been adopted by the MathWorks Aerospace Leadership Council (MALC). General Electric Transportation Systems (GETS) is a well known railway signaling systems manufacturer leading in Automatic Train Protection (ATP) systems technology. Inside an effort of adopting formal methods within its own development process, GETS decided to introduce system modeling by means of the MathWorks tools [2], and in 2008 chose to move to code generation. This article reports the experience performed by GETS in developing its own modeling standard through customizing the MAAB rules for the railway signaling domain and shows the result of this experience with a successful product development story.

Ferrari, Alessio

The Net Carbon Flux due to Deforestation and Forest Re-Growth in the Brazilian Amazon: Analysis using a Process-Based Model

We developed a process-based model of forest growth, carbon cycling, and land cover dynamics named CARLUC (for CARbon and Land Use Change) to estimate the size of terrestrial carbon pools in terra firme (non-flooded) forests across the Brazilian Legal Amazon and the net flux of carbon resulting from forest disturbance and forest recovery from disturbance. Our goal in building the model was to construct a relatively simple ecosystem model that would respond to soil and climatic heterogeneity that allows us to study of the impact of Amazonian deforestation, selective logging, and accidental fire on the global carbon cycle. This paper focuses on the net flux caused by deforestation and forest re-growth over the period from 1970-1998. We calculate that the net flux to the atmosphere during this period reached a maximum of approx. 0.35 PgC/yr (1PgC = 1 x 10(exp I5) gC) in 1990, with a cumulative release of approx. 7 PgC from 1970- 1998. The net flux is higher than predicted by an earlier study by a total of 1 PgC over the period 1989-1 998 mainly because CARLUC predicts relatively high mature forest carbon storage compared to the datasets used in the earlier study. Incorporating the dynamics of litter and soil carbon pools into the model increases the cumulative net flux by approx. 1 PgC from 1970-1998, while different assumptions about land cover dynamics only caused small changes. The uncertainty of the net flux, calculated with a Monte-Carlo approach, is roughly 35% of the mean value (1 SD).

Hirsch, A. I.

A Model-Based Approach to Developing Your Mission Operations System

Model-Based System Engineering (MBSE) is an increasingly popular methodology for designing complex engineering systems. As the use of MBSE has grown, it has begun to be applied to systems that are less hardware-based and more people- and process-based. We describe our approach to incorporating MBSE as a way to streamline development, and how to build a model consisting of core resources, such as requirements and interfaces, that can be adapted and used by new and upcoming projects. By comparing traditional Mission Operations System (MOS) system engineering with an MOS designed via a model, we will demonstrate the benefits to be obtained by incorporating MBSE in system engineering design processes.

mos

Developing A Dependable Multi-Agent Rover Swarm Using cFS

The future of space exploration lies in cooperative autonomous systems. Ensuring their high integrity remains a challenge. The Robust Software Engineering group at NASA Ames Research Center has been developing the Troupe project to explore the challenges with developing and assuring high integrity of cooperative autonomous robotic systems. In particular, Troupe aims to develop a swarm of autonomous rovers capable of mapping unknown terrain and assure their high integrity using the advanced V&V tools developed in the group. In this paper, we present the evolution of the design of Troupe. We focus on the lessons learned in developing and assuring the rover swarm using core Flight System (cFS). In particular, we discuss the benefits and challenges in applying model-based development to develop the rover swarm.

space systems

Developing A Dependable Multi-Agent Rover Swarm Using cFS

The future of space exploration lies in cooperative autonomous systems. Ensuring their high integrity remains a challenge. The Robust Software Engineering group at NASA Ames Research Center has been developing the Troupe project to explore the challenges with developing and assuring high integrity of cooperative autonomous robotic systems. In particular, Troupe aims to develop a swarm of autonomous rovers capable of mapping unknown terrain and assure their high integrity using the advanced V&V tools developed in the group. In this paper, we present the evolution of the design of Troupe. We focus on the lessons learned in developing and assuring the rover swarm using core Flight System (cFS). In particular, we discuss the benefits and challenges in applying model-based development to develop the rover swarm.

space systems

Model-Based Safety Analysis

System safety analysis techniques are well established and are used extensively during the design of safety-critical systems. Despite this, most of the techniques are highly subjective and dependent on the skill of the practitioner. Since these analyses are usually based on an informal system model, it is unlikely that they will be complete, consistent, and error free. In fact, the lack of precise models of the system architecture and its failure modes often forces the safety analysts to devote much of their effort to gathering architectural details about the system behavior from several sources and embedding this information in the safety artifacts such as the fault trees. This report describes Model-Based Safety Analysis, an approach in which the system and safety engineers share a common system model created using a model-based development process. By extending the system model with a fault model as well as relevant portions of the physical system to be controlled, automated support can be provided for much of the safety analysis. We believe that by using a common model for both system and safety engineering and automating parts of the safety analysis, we can both reduce the cost and improve the quality of the safety analysis. Here we present our vision of model-based safety analysis and discuss the advantages and challenges in making this approach practical.

Joshi, Anjali

Software Safety Analysis of a Flight Guidance System

This document summarizes the safety analysis performed on a Flight Guidance System (FGS) requirements model. In particular, the safety properties desired of the FGS model are identified and the presence of the safety properties in the model is formally verified. Chapter 1 provides an introduction to the entire project, while Chapter 2 gives a brief overview of the problem domain, the nature of accidents, model based development, and the four-variable model. Chapter 3 outlines the approach. Chapter 4 presents the results of the traditional safety analysis techniques and illustrates how the hazardous conditions associated with the system trace into specific safety properties. Chapter 5 presents the results of the formal methods analysis technique model checking that was used to verify the presence of the safety properties in the requirements model. Finally, Chapter 6 summarizes the main conclusions of the study, first and foremost that model checking is a very effective verification technique to use on discrete models with reasonable state spaces. Additional supporting details are provided in the appendices.

Butler, Ricky W.

Portable Wireless LAN Device and Two-Way Radio Threat Assessment for Aircraft VHF Communication Radio Band

This document summarizes the safety analysis performed on a Flight Guidance System (FGS) requirements model. In particular, the safety properties desired of the FGS model are identified and the presence of the safety properties in the model is formally verified. Chapter 1 provides an introduction to the entire project, while Chapter 2 gives a brief overview of the problem domain, the nature of accidents, model based development, and the four-variable model. Chapter 3 outlines the approach. Chapter 4 presents the results of the traditional safety analysis techniques and illustrates how the hazardous conditions associated with the system trace into specific safety properties. Chapter 5 presents the results of the formal methods analysis technique model checking that was used to verify the presence of the safety properties in the requirements model. Finally, Chapter 6 summarizes the main conclusions of the study, first and foremost that model checking is a very effective verification technique to use on discrete models with reasonable state spaces. Additional supporting details are provided in the appendices.

Nguyen, Truong X.