An Approach to Verification and Validation in Large Scale System of Systems

Kirstie L. Bellman · AIAA Infotech@Aerospace 2010 · 2010

e begin our discussion of the type of verification and validation (V&V) approaches needed in very large, complex, space systems by focusing first on some new approaches for the V&V of Fault Management Systems (FMS). This is because the problems of a FMS are representative of the problems of providing an integrated assessment of sufficiency and correctness across a large distributed system with enormously diverse components. We then generalize the strategy underlying this approach to other complicated aspects of verifying and validating space systems from design and development to operations. One critical function in modern flight software is to monitor hardware and software subsystem behaviors, to identify pre-defined anomalies, to provide the appropriate response from a limited repertoire of corrective actions and to alert the operators on the ground to continue additional corrective actions as needed. Traditionally the FMS responded only to hardware failures and critical anomalies, but in several software-intensive space systems designs, certain critical software errors are now being included. The FMS is expected to operate during all mission phases to protect the spacecraft (S/C), e.g. during ascent, transfer orbit and mission orbit when fully deployed. One of the chief requirements of the FMS is to “safe” the S/C, which may include switching to redundant components as needed in subsystems such as GNC (Guidance, Navigation, and Control), power, thermal, etc., as well as placing the S/C in a sun-safe attitude and placing the payload into a safe configuration. As can be seen from even this brief description, the FMS must correctly collect and integrate the information from a broad range of conditions, involving the characterization of a complicated set of measures and fault conditions and then it must decide and respond quickly enough with an ordered set of safing responses. In order to test the correctness and the adequacy of the FMS, developers spend hundreds of hours producing specifications and design documents and testing code, nearly matched in hours by the government reviewers. Because relevant FMS specifications may be necessarily scattered over a number of specification documents, it is especially difficult to assess the overall completeness (have all pertinent forms of the fault case been covered) or consistency (are any of the fault procedures mutually contradictory when conditions combine them). Similarly, during code development, it may be difficult to test all the relevant FMS code, especially when relevant code may include both the flight software as well as distributed embedded code segments, co-located with components throughout the space system. Because of the time-intensive nature of this evaluation, many space systems end up running out of time, resulting in an increased risk that vital parts of the anomaly detection or corrective responses will not perform as desired during flight.

Read the paper · More papers on PaperTik