Submitted:
28 June 2023
Posted:
06 July 2023
You are already at the latest version
Abstract
Keywords:
1. Introduction
2. Methodology
3. Demonstration Case
3.1. Scenario Description
3.2. Assumptions and Simplifications
3.3. Navigation System Fault Tree
3.4. Modeling Kalman filter software failures using dual graph error propagation method (DEPM)
3.5. Modeling Total Ionizing Dose limits for Electronic Hardware
4. Results and Discussion
4.1. Probability of Loss of Mission (LOM) using Commercial-Off-The-Shelf (COTS) Components
4.2. Selective Radiation Hardening using Mission Success Criteria
5. Conclusion
Author Contributions
Funding
Conflicts of Interest
References
- M. I. Ahmad, M. H. Ab. Rahim, R. Nordin, F. Mohamed, A. Abu-Samah, and N. F. Abdullah, “Ionizing Radiation Monitoring Technology at the Verge of Internet of Things,” Sensors, vol. 21, no. 22, p. 7629, Nov. 2021. [CrossRef]
- L. R. Pinto et al., “Radiological Scouting, Monitoring and Inspection Using Drones,” Sensors, vol. 21, no. 9, p. 3143, Apr. 2021. [CrossRef]
- B. J. Garrick, Quantifying and Controlling Catastrophic Risks. Academic Press, 2008.
- W.E. Vesely,F.F. Goldberg,N.H. Roberts,D.F. Haasl, “NUREG-0492, ‘Fault Tree Handbook’.” Jan. 1981. [Online]. Available: https://drum.lib.umd.edu/handle/1903/7729. 1903.
- S. A. Kripke, “Semantical Considerations on Modal Logic,” Acta Philos. Fenn., vol. 16, pp. 83–94, 1963, [Online]. Available: http://saulkripkecenter.org/wp-content/uploads/2019/03/Semantical-Considerations-on-Modal-Logic-PUBLIC.pdf.
- M. Kwiatkowska, G. M. Kwiatkowska, G. Norman, and D. Parker, “Stochastic Model Checking,” in Formal Methods for Performance Evaluation, M. Bernardo and J. Hillston, Eds., in Lecture Notes in Computer Science, vol. 4486. Berlin, Heidelberg: Springer Berlin Heidelberg, 2007, pp. 220–270. https://doi.org/10.1007/978-3-540-72522-0_6. [CrossRef]
- C. Baier and J.-P. Katoen, Principles of model checking. Cambridge, Mass: The MIT Press, 2008.
- K. Schneider, Verification of reactive systems: formal methods and algorithms. in Texts in theoretical computer science. Berlin ; New York: Springer-Verlag, 2004 .
- M. O. Rabin and D. Scott, “Finite Automata and Their Decision Problems,” IBM J. Res. Dev., vol. 3, no. 2, pp. 114–125, Apr. 1959. [CrossRef]
- M. A. Diaconeasa and A. Mosleh, “The ADS-IDAC Dynamic Platform with Dynamically Linked System Fault Trees,” Philadelphia, PA, 2017.
- Morozov and K. Janschek, “Dual Graph Error Propagation Model for Mechatronic System Analysis,” IFAC Proc. Vol., vol. 44, no. 1, pp. 9893–9898, Jan. 2011. [CrossRef]
- V. Vidineev, N. Yusupova, K. Ding, A. Morozov, and K. Janschek, “Improved stochastic control flow model for LLVM-based software reliability analysis,” Ind. 40, vol. 3, no. 4, pp. 172–174, 2018, Accessed: Aug. 02, 2022. [Online]. Available: https://stumejournals.com/journals/i4/2018/4/172.
- K. Ding, S. Ding, A. Morozov, T. Fabarisov, and K. Janschek, “On-Line Error Detection and Mitigation for Time-Series Data of Cyber-Physical Systems using Deep Learning Based Methods,” in 2019 15th European Dependable Computing Conference (EDCC), Naples, Italy: IEEE, Sep. 2019, pp. 7–14. [CrossRef]
- J. Marques-silva, “Practical applications of boolean satisfiability,” in In Workshop on Discrete Event Systems (WODES, IEEE Press, 2008.
- R. E. Bryant and M. J. Heule, “Generating extended resolution proofs with a BDD-based SAT solver,” in International Conference on Tools and Algorithms for the Construction and Analysis of Systems, Springer, 2021, pp. 76–93.
- K. Vetter, “The Institute of Resilient Communities,” in Resilience: A New Paradigm of Nuclear Safety, J. Ahn, F. Guarnieri, and K. Furuta, Eds., Cham: Springer International Publishing, 2017, pp. 207–218. [CrossRef]
- K. Vetter, “Multi-sensor radiation detection, imaging, and fusion,” Nucl. Instrum. Methods Phys. Res. Sect. Accel. Spectrometers Detect. Assoc. Equip., vol. 805, pp. 127–134, Jan. 2016. [CrossRef]
- G.U. Medvedevs, “JPRS Report, Soviet Union: Economic Affairs (‘Chernobyl Notebook’),” Soviet Union: Economic Affairs, JPRS-UEA-89-034, Oct. 1989. Accessed: Jun. 19, 2023. [Online]. Available: https://apps.dtic.mil/sti/pdfs/ADA335076.pdf.
- OpenPRA Community, “OpenPRA Initiative,” Apr. 01, 2019. https://openpra.org/ (accessed Jan. 17, 2022).
- “Texas Instruments - Reliability Testing,” Texas Instruments Quality & Reliability. https://www.ti.com/support-quality/reliability/reliability-testing.html (accessed Jan. 10, 2022).
- Earthperson, C. M. Otani, D. Nevius, S. R. Prescott, and M. A. Diaconeasa, “A combined strategy for dynamic probabilistic risk assessment of fission battery designs using EMRALD and DEPM,” Prog. Nucl. Energy, vol. 160, p. 104673, Jun. 2023. [CrossRef]
- “GSFC Radiation Data Base.” https://radhome.gsfc.nasa.gov/radhome/RadDataBase/RadDataBase.html (accessed Jun. 16, 2023).
- G. Bazzano et al., “Radiation testing of a commercial 6-axis MEMS inertial navigation unit at ENEA Frascati proton linear accelerator,” Adv. Space Res., vol. 67, no. 4, pp. 1379–1391, Feb. 2021. [CrossRef]
- J. Qiu et al., “Effects of neutron and gamma radiation on lithium-ion batteries,” Nucl. Instrum. Methods Phys. Res. Sect. B Beam Interact. Mater. At., vol. 345, pp. 27–32, Feb. 2015. [CrossRef]
- M. Markgraf and O. Montenbruck, “Total Ionizing Dose Testing of the Orion and Phoenix GPS Receivers,” German Space Operations Center (GSOC), TN 04-01, Feb. 2004. [Online]. Available: https://www.dlr.de/rb/Portaldata/38/Resources/dokumente/GSOC_dokumente/RB-RFT/TN_0401.pdf.
- N. Rezzak, J.-J. Wang, C.-K. Huang, V. Nguyen, and G. Bakker, “Total Ionizing Dose Characterization of 65 nm Flash-Based FPGA,” in 2014 IEEE Radiation Effects Data Workshop (REDW), Paris, France: IEEE, Jul. 2014, pp. 1–5.
| 1 | If the source set equals the domain, is left-total.
|
| 2 |
– Normal distribution, truncated to represent a realistic and physically meaninginful sampling space. For example, time cannot be negative.
|
| 3 |
– Loguniform distribution with and
|










| Term | Definition | Description |
|---|---|---|
| A set of possible states | ||
| The initial state, which is nominal | ||
| is fully-connected. |
| Regular Expression | Term | Description |
|---|---|---|
| A* | Ideal/Perfect System | No errors, faults, or failures occur. |
| B | Fault | A fault is a weakness that can potentially lead to errors. |
| DF*|C+ | Error Propagation | Move from an initial error state leads to a subsequent one. |
| D|I | Failure | System fails from either a degraded or a nominal state. |
| E|G|H | Recoverable System | Move from higher to lower degradation. |
| B(C*|E) | Fault Tolerant | Avoid transition to failure, given a fault. |
| A*|(B(C*|E)) | Failure Avoidant | No failures occur. |
| G|H | Resilient System | Recover from a failure, either fully or partially. |
| B(C*|D(F*|G))|(I(F*|G)) | Irrecoverable System | Neither completely fails, nor returns to nominal. |
| F+ | Permanently Failed | System remains irrecoverable forever. |
| Term | Definition |
|---|---|
| A set of elements, always non-empty. | |
| A set of optional data terms. | |
| An edge-list representing control flows. | |
| An edge-list representing data flows. | |
| . |
| Element | Conditional Expressions |
|---|---|
| A |
always: with P(0.8): DATA VARIABLE 1, DATA VARIABLE 2 = error with P(0.2): DATA VARIABLE 1, DATA VARIABLE 2 = ok |
| B |
if DATA VARIABLE 1 = error, then: with P(0.9): DATA VARIABLE 2 = ok with P(0.1): DATA VARIABLE 2 = errorelse: with P(1.0): DATA VARIABLE 2 = ok |
| C |
if DATA VARIABLE 2 & DATA VARIABLE 3 = ok, then: with P(1.0): DATA VARIABLE 4 = okelse: with P(0.2): DATA VARIABLE 4 = ok with P(0.8): DATA VARIABLE 4 = error |
| Zone | Dose Rate[rad/hour] | Elapsed Time[minute] | Total Received Dose[rad] |
|---|---|---|---|
| A | |||
| B | |||
| C |
| Basic Event | Part Number | Component Type | Derated Failure Rate] |
|---|---|---|---|
| SENSOR_IMU | TI-MSP430 Series | MEMS IMU | |
| CAM_HW | TI-TDA4AL-Q1 | Vision SoC + DSP | |
| RAD_HW | TI-IWR1642AQAGABL | mmWave Radar + DSP | |
| DSP_KAL | TI-TMS320C6678 | Kalman Filter DSP |
| Basic Event | Basic Event Description | Failure Rate] |
|---|---|---|
| SENSOR_IMU | Inertial Measurement Unit Failure | |
| CAM_HW | Vision System-on-Chip Module Failure | |
| RAD_HW | mmWave Radar Module Failure | |
| DSP_KAL | Filter DSP Hardware Failure | |
| CODE_KAL | Kalman Filter Software Failure | DEPM, see section on Page 12 |
| GPS_HW | GPS Sensor Module Failure | |
| GPS_LOSSY | Lossy GPS Signal | |
| SUPPLY_POW | Switching Power Supply Circuit Failure | |
| BATT_LOW | Battery Low | Time dependent, see Figure 6 |
| BATT_LOSS | Post Irradiation Battery Capacity Loss | P = 1 as TID approaches TID limit |
| /*** Kalman Filter (Single Variable) * Assume the input is in register R0 * Assume the initial state estimate is in register R1 * Assume the initial error covariance is in register R2 * Assume the process noise variance is in register R3 * Assume the measurement noise variance is in register R4 **/ Initialization 1. MOV R5, R1 // R5 = State estimate (copy of initial state estimate) 2. MOV R6, R2 // R6 = Error covariance (copy of initial error covariance) LOOP: Prediction step 4. MOV R7, R5 // R7 = Predicted state estimate (copy of state estimate) 5. ADD R5, R7 // R5 = State estimate = State estimate + Predicted state estimate 6. MOV R8, R6 // R8 = Predicted error covariance (copy of error covariance) 7. ADD R8, R3 // R8 = Predicted error covariance + Process noise variance 8.MOV R6, R8 // R6 = Error covariance = Predicted error covariance + Process noise variance Update step 9. MOV R9, R6 // R9 = Error covariance (copy of error covariance) 10. ADD R9, R4 // R9 = Error covariance + Measurement noise variance 11. MOV R10, R9 // R10 = Temporary variable for division 12. DIV R8, R10 // R8 = Kalman gain = Error covariance / (Error covariance + Measurement noise variance) 13. MOV R11, R0 // R11 = Measurement 14. SUB R11, R7 // R11 = Measurement - Predicted state estimate 15. MUL R11, R8 // R11 = Innovation = (Measurement - Predicted state estimate) * Kalman gain 16. ADD R5, R11 // R5 = State estimate = State estimate + Innovation 17. MOV R12, R8 // R12 = Kalman gain (copy of Kalman gain) 18. SUB R12, R8 // R12 = 1 - Kalman gain 19. MUL R6, R12 // R6 = Error covariance = Error covariance * (1 - Kalman gain) // Continue the loop or terminate |
| Component | Commercial Off The Shelf(COTS) |
|---|---|
| Inertial Measurement Unit | |
| Power Switching Circuit | |
| Lithium Ion Battery | |
| GPS Sensor Module | |
| Vision SoC Module | |
| mmWave Radar Module | |
| Filter DSP Hardware |
| End State | End State Description | P(End State) |
|---|---|---|
| Loss of Mission in Zone A | ||
| Loss of Mission in Zone B | ||
| Loss of Mission in Zone C | ||
| Mission Success |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2023 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).