Search NASA⌕ Search

SEARCH · Search NASA

Results for “Secure by Design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 199 records · Page 11

NASA Electronic Library System (NELS): The system impact of security

This paper discusses security issues as they relate to the NASA Electronic Library System which is currently in use as the repository system for AdaNET System Version 3 (ASV3) being operated by MountainNET, Inc. NELS was originally designed to provide for public, development, and secure collections and objects. The secure feature for collections and objects was deferred in the initial system for implementation at a later date. The NELS system is now 9 months old and many lessons have been learned about the use and maintenance of library systems. MountainNET has 9 months of experience in operating the system and gathering feedback from the ASV3 user community. The user community has expressed an interest in seeing security features implemented in the current system. The time has come to take another look at the whole issue of security for the NELS system. Two requirements involving security have been put forth by MountainNET for the ASV3 system. The first is to incorporate at the collection level a security scheme to allow restricted access to collections. This should be invisible to end users and be controlled by librarians. The second is to allow inclusion of applications which can be executed only by a controlled group of users; for example, an application which can be executed by librarians only. The requirements provide a broad framework in which to work. These requirements raise more questions than answers. To explore the impact of these requirements a top down approach will be used.

Mcgregor, Terry L.↗

Kilopower: Small and Affordable Fission Power Systems for Space

The Nuclear Systems Kilopower Project was initiated by NASA's Space Technology Mission Directorate Game Changing Development Program in fiscal year 2015 to demonstrate subsystem-level technology readiness of small space fission power in a relevant environment (Technology Readiness Level 5) for space science and human exploration power needs. The Nuclear Systems Kilopower Project centerpiece is the Kilopower Reactor Using Stirling Technology (KRUSTY) test, which consists of the development and testing of a fission ground technology demonstrator of a 1 kWe-class fission power system. The technologies to be developed and validated by KRUSTY are extensible to space fission power systems from 1 to 10 kWe, which can enable higher power future potential deep space science missions, as well as modular surface fission power systems for exploration. The Kilopower Project is cofounded by NASA and the Department of Energy National Nuclear Security Administration (NNSA).KRUSTY include the reactor core, heat pipes to transfer the heat from the core to the power conversion system, and the power conversion system. Los Alamos National Laboratory leads the design of the reactor, and the Y-12 National Security Complex is fabricating it. NASA Glenn Research Center (GRC) has designed, built, and demonstrated the balance of plant heat transfer and power conversion portions of the KRUSTY experiment. NASA MSFC developed an electrical reactor simulator for non-nuclear testing, and the design of the reflector and shielding for nuclear testing. In 2016, an electrically heated non-fissionable Depleted Uranium (DU) core was tested at GRC in a configuration identical to the planned nuclear test. Once the reactor core has been fabricated and shipped to the Device Assembly Facility at the NNSAs Nevada National Security Site, the KRUSTY nuclear experiment will be assembled and tested. Completion of the KRUSTY experiment will validate the readiness of 1 to 10 kWe space fission technology for NASAs future requirements for sunlight-independent space power. An early opportunity for demonstration of In-Situ Resource Utilization (ISRU) capability on the surface of Mars is currently being considered for 2026 launch. Since a space fission system is the leading option for power generation for the first Mars human outpost, a smaller version of a planetary surface fission power system could be built to power the ISRU demonstration and ensure its end-to-end validity. Planning is underway to start the hardware development of this subscale flight demonstrator in 2018.

Space nuclear power↗

A Visual Analytic Platform for Interactive Validation of Human Mobility Simulations

Human mobility insights guide domain experts in an array of decisions, including critical infrastructure design, disaster response, epidemic modeling, national security, and policy making. Due to the inherent noise and privacy concerns in real-world individual-level mobility data, it is often preferred to leverage simulators that generate synthetic mobility data instead. However, it is critical to inspect and validate the output of such simulators to ensure the synthetic data is aligned with the characteristics of the population and the area of interest known to domain experts. While there exist many quantitative approaches for validating synthetic data, we argue it is also important to also validate such data qualitatively to capture aspects that are known to domain experts but difficult to quantify. In this work, we demonstrate a visual analytic platform that empowers domain experts to interact with their simulation outputs along spatial and temporal dimensions. By augmenting automated techniques and human skills, our visual analytic platform is a step towards interactive capabilities for model steering and quality control of mobility simulators.

Monadjemi, Shayan↗

Dynamic verification of very large space structures

The dynamic verification of spacecraft relies heavily on ground-based tests. These tests usually simulate flight environments or validate analytical models used in establishing design loads and in designing control algorithms. They also provide security against failures resulting from unanticipated or unmodeled hardware behavior. Future orbital antennas, space stations, and solar power systems are likely to be of sizes difficult to test using current ground test technology. In addition to size, other factors such as low natural frequencies, lightweight construction, and the presence of many structural joints, cause significant sensitivity of the test process to the earth-gravity environment. Yet, accuracy requirements on the verification process will be more stringent because of modern flexible-structure control approaches. This paper describes some of the problems and discusses research on potential solutions. The importance of an integrated ground test, analysis, and flight test program is emphasized. An ongoing research program of this type focusing on a 60-meter, deployable, truss-beam test article is described.

Hanks, B. R.↗

SSME hot gas manifold flow comparison test

An account is given of the High Pressure Fuel Turbopump (HPFT) component of NASA's Alternate Turbopump Development effort, which is aimed at the proper aerodynamic integration of the current Phase II three-duct SSME Hot Gas Manifold (HGM) and the future 'Phase II-plus' two-duct HGM. Half-scale water flow tests of both HGM geometries were conducted to provide initial design data for the HPFT. The results reveal flowfield results and furnish insight into the performance differences between the two HGM flowpaths. Proper design of the HPFT can potentially secure significant flow improvements in either HGM configuration.

Cox, G. B., Jr.↗

Redefining Tactical Operations for MER Using Cloud Computing

The Mars Exploration Rover Mission (MER) includes the twin rovers, Spirit and Opportunity, which have been performing geological research and surface exploration since early 2004. The rovers' durability well beyond their original prime mission (90 sols or Martian days) has allowed them to be a valuable platform for scientific research for well over 2000 sols, but as a by-product it has produced new challenges in providing efficient and cost-effective tactical operational planning. An early stage process adaptation was the move to distributed operations as mission scientists returned to their places of work in the summer of 2004, but they would still came together via teleconference and connected software to plan rover activities a few times a week. This distributed model has worked well since, but it requires the purchase, operation, and maintenance of a dedicated infrastructure at the Jet Propulsion Laboratory. This server infrastructure is costly to operate and the periodic nature of its usage (typically heavy usage for 8 hours every 2 days) has made moving to a cloud based tactical infrastructure an extremely tempting proposition. In this paper we will review both past and current implementations of the tactical planning application focusing on remote plan saving and discuss the unique challenges present with long-latency, distributed operations. We then detail the motivations behind our move to cloud based computing services and as well as our system design and implementation. We will discuss security and reliability concerns and how they were addressed

Mars↗

Spaceflight Holography Investigation in a Virtual Apparatus (SHIVA) Ground Experiments and Concepts for Flight Design

This paper discusses the development and design of an experimental test cell for ground-based testing to provide requirements for the Spaceflight Holography Investigation in a Virtual Apparatus (SHIVA) experiment. Ground-based testing of a hardware breadboard set-up is being conducted at Marshall Space Flight Center in Huntsville, Alabama. SHIVA objectives are to test and validate new solutions of the general equation of motion of a particle in a fluid, including particle-particle interaction, wall effects, motion at higher Reynolds Number, and a motion and dissolution of a crystal moving in a fluid. These objectives will be achieved by recording a large number of holograms of particle motion in the International Space Station (ISS) glove box under controlled conditions, extracting the precise three- dimensional position of all the particles as a function of time, and examining the effects of all parameters on the motion of the particles. This paper will describe the mechanistic approach to enabling the SHIVA experiment to be performed in a ISS glove box in microgravity. Because the particles are very small, surface tension becomes a major consideration in designing the mechanical method to meet the experiments objectives in microgravity, To keep a particle or particles in the center of the test cell long enough to perform and record the experiment and to preclude contribution to particle motion, requires avoiding any initial velocity in particle placement. A Particle Injection Mechanism (PIM) designed for microgravity has been devised and tested to enable SHIVA imaging. Also, a test cell capture mechanism, to secure the test cell during vibration on a specially designed shaker table for the SHIVA experiment will be described. Concepts for flight design are also presented.

Miernik, Janie H.↗

Defensive Cybersecurity Architecture Design Using Force-on-Force Cyber-Physical Modeling

Currently, nuclear power plant physical security systems are highly dependent on air-gaps as a protective measure against cyber-threats. Cyber-physical threats become more likely as advanced cyber-threat capabilities to jump air-gaps transition into common use. Defending against the emerging threat of cyber-enabled physical intrusions is poorly understood. The consequence of these cyber-physical attacks has no quantitative analysis method to inform risk-informed, performance-based cybersecurity approaches. By modifying the physical security simulation tool Dante, cyber-physical threat consequence was able to be analyzed on a notional facility. The results of this analysis are used to design a Defensive Cybersecurity Architecture (DCSA) for the physical security system to produce example resilience measures for this notional facility. A DCSA defines security levels to provide a graded approach for defending plant functions, and security zones for trusted communication between systems. This approach can be applied to real world systems to produce physical protection systems and response measures that are resilient to cyber-physical threats.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

LLGOMAX: Enhancing Industry-Standard Tools for AC Optimal Unit Commitment (CRADA Final Report)

This was a collaborative effort between Lawrence Livermore National Security, LLC ("LLNS"), as manager and operator of Lawrence Livermore National Laboratory ("LLNL") and ECCO International Inc. ("Participant"). The team designed and implemented a new approach for the Security-Constrained Alternating-Current Unit Commitment (SCACUC) problem. The SCACUC problem is a mathematical optimization problem that decides which generating units should be online and how much power should be produced (and consumed) at each point of the power grid. The decisions are made so as to minimize the total cost of supplying electricity while respecting technical constraints of the power grid, both under normal and emergency conditions. The team developed a solution for SCACUC as specified in the ARPA-E Grid Optimization Competition (GOC) Challenge 3, which put forth a forward-looking version of the problem, which many features not present in today’s electricity market specifications for SCACUC.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Secured Advanced Federated Environment (SAFE): A NASA Solution for Secure Cross-Organization Collaboration

This paper discusses the challenges and security issues inherent in building complex cross-organizational collaborative projects and software systems within NASA. By applying the design principles of compartmentalization, organizational hierarchy and inter-organizational federation, the Secured Advanced Federated Environment (SAFE) is laying the foundation for a collaborative virtual infrastructure for the NASA community. A key element of SAFE is the Micro Security Domain (MSD) concept, which balances the need to collaborate and the need to enforce enterprise and local security rules. With the SAFE approach, security is an integral component of enterprise software and network design, not an afterthought.

Chow, Edward↗

From Modular ADMS to Plug-and-Play Ops: Distribution Grid Operations with Platform-Level Orchestration to Enable Ambitious App Hosting

The core function of the distribution grid is to provide electricity to consumers affordably, reliably, and securely. In pursuing these core objectives, distribution utilities are accountable to customers, regulators, and in some cases, shareholders. Other third parties such as aggregators and microgrids can also have a stake in the smooth operation of the grid. Each of these stakeholders has economic, business, and/or governance objectives that inform their expectations of the distribution grid. This multi-objective, multi-stakeholder environment creates tension that must be reconciled to successfully design and operate the distribution grid. Innovative companies are competing to bring high-tech solutions to electric utilities and their customers that address each of these objectives. Many developers of advanced distribution management systems (ADMS) and distributed energy resource management systems (DERMS) have adopted a modular architecture that allows grid operators to select functions and features according to their individual system needs. A modular platform also allows the solution provider to develop and integrate specific new product modules; however, the need to pursue multiple objectives with a fixed set of controllable devices makes integration expensive whether it is done at the product development stage or the deployment stage. This cost creates a significant barrier to adoption and can lengthen the product to market time of new solutions. To fundamentally address the complexity of system integration for distribution grid operations, the U.S. Department of Energy Office of Electricity has funded the GridAPPS-D project at PNNL, which streamlines integration by contributing to standards development, defining system architecture, applying advanced mathematics, and developing open-source software to demonstrate the concept of an open data-integration platform for distribution operations. The open data-integration platform concept enables system operators and solution providers to deploy ambitious, best-of-breed applications (or apps) without continually reengineering for integration. Ambitious apps developed by different solution providers will inevitably attempt to achieve different control objectives with the same set of controllable devices. If the open platform itself can resolve these conflicts in a way that achieves the best available outcomes for all apps, doesn’t restrict the ambitious design of apps, and ensures safe and secure operations, apps will be able to plug-and-play with the platform at the same time as other ambitious apps. In this paper, we describe a framework called App Deconfliction that empowers a platform to assign setpoints to controllable devices based on the values preferred by different apps (and even external stakeholder entities like customers or aggregators). The App Deconfliction framework is compatible with several methods for determining setpoint values. We present two methods based on game theory that provide a subtle built-in incentive structure for developers to adapt their apps to the fact that they will be operating in a moderated multi-app environment and to favor device setpoints that have the most effect on their objectives over those that have the least effect. Our simulation-based demonstrations have shown that game-theory-based deconfliction can lead to a 7% improvement in control space utilization compared to design-based methods.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Building a Trusted Roaming Hub [Slides]

The Trusted Roaming Hub is a U.S. Department of Energy-backed initiative led by the National Laboratory of the Rockies (NLR) to address one of the most persistent challenges in electric vehicle (EV) charging: fragmented roaming, inconsistent interoperability, and insufficient digital trust across charging networks. As EV adoption accelerates and charging infrastructure scales nationwide, today's many-to-many integration model between eMobility Service Providers (eMSPs) and Charge Point Operators (CPOs) has become increasingly brittle, costly, and difficult to secure. The Trusted Roaming Hub introduces a neutral, cybersecurity-forward "switchboard" architecture that enables standardized, secure, and scalable roaming interactions across the EV charging ecosystem. Rather than replacing existing networks or commercial relationships, the hub acts as a trusted intermediary that enforces consistent identity, authentication, authorization, and routing across participants improving reliability for drivers, lowering integration burden for industry, and creating a foundation for future grid-interactive charging services. This read-ahead provides an overview of the problem the hub is designed to solve, the core functional and security concepts behind the architecture, the value proposition to key stakeholders, and the near-term trajectory of the work.

33 ADVANCED PROPULSION SYSTEMS↗

CIE Curriculum Guide (V.2.0)

The Cyber-Informed Engineering (CIE) Curriculum Guide offers a comprehensive framework, guidance, and resources for integrating CIE into university-level engineering programs and related educational activities. The primary goal is to help educators adopt CIE principles into their teaching to produce future engineers and technicians who understand digital risks in modern engineered systems, thereby addressing the nation’s infrastructure resilience needs. This guide outlines practical integration examples, links to resources to accelerate CIE adoption, and shares insights from partner academic institutions on various implementation strategies. CIE is a framework for embedding engineered controls that mitigate the impact of cyber-attacks in any cyber-physical system used in critical energy infrastructure and other sectors. Developed by the U.S. Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER), the National Cyber-Informed Engineering Strategy emphasizes embedding CIE into formal education, training, and credentialing. This guide supports this strategic objective by providing examples of integrating CIE concepts into engineering curricula, from class activities to new courses and certificate programs. The importance of educating cyber-informed engineers is underscored by the evolving cybersecurity threats facing engineered systems. As industrial control systems (ICS) increasingly incorporate digital technologies, the responsibility for security extends to both cyber professionals and engineers. CIE addresses critical gaps in designing and protecting physical systems with digital components against cyber risks, ensuring engineers consider digital risk throughout the engineering design lifecycle. Currently, engineering education does not routinely include cyber-informed principles, highlighting a gap in addressing modern engineering system risks. This guide advocates for updating engineering curricula to include digital risk management as a fundamental element. By doing so, future engineers will be equipped to design resilient systems that mitigate digital risks from the outset. Through this guide, engineering faculty can integrate CIE into their curricula, bridging the gap between digital risk and engineering. This approach prepares a cyber-informed workforce capable of safeguarding the cyber-physical systems crucial to national security and public welfare. By embedding CIE into education and training, institutions can produce engineers and technicians who can effectively mitigate cyber impacts throughout the engineering design lifecycle, resulting in more secure critical infrastructures.

42 - ENGINEERING↗

Evaluation of Real-Time Mitigation Techniques forCyber Security in IEC 61850 / IEC 62351Substations

This paper presents the design logic and implementation aspects of three potential real-time mitigation techniques capable of countering GOOSE-based attacks: (i) IEC 62351-compliant message authentication code (MAC) scheme, (ii) a semantics-enforced rule- based intrusion detection system (IDS), and (iii) a hybrid approach integrating both MAC verification and Intrusion Detection System (IDS). A comparative evaluation of these real-time mitigation approaches is conducted using a cyber-physical system(CPS) security testbed. The results show that the hybrid integration significantly enhances mitigation capability. Furthermore, the processing delays of all three methods remain within the strict delivery requirements of GOOSE communication. The study also identifies limitations that none of the techniques can fully address, highlighting areas for future work.

Liu, Chen-Ching [Virginia Polytechnic Inst. and St↗

Advanced Reactor Safeguards & Security Program: Cybersecurity Scenarios

The use of digital control systems and automation in advanced nuclear power systems introduces different types of vulnerabilities compared to legacy (i.e. analog) control systems that cyber adversaries can exploit. These vulnerabilities pose a challenge to reactor operators and cyber operations staff due to the dynamic nature of the event in which a human response or a lack of response can potentially evolve into a worsening plant condition. Using the Department of Homeland Security Cyber and Infrastructure Security Agency’s (CISA) critical infrastructure exercise framework, this document presents several cyber security scenarios typical of digital control systems that could be used in advanced reactor designs. These scenarios can be used in tabletop exercises to evaluate cyber security posture or conduct training on different aspects of cyber security, including detection, threat hunting using indicators of compromise, evaluating incident response, risk mitigation, incident reporting, information sharing and recovery.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Operational Concepts for a Generic Space Exploration Communication Network Architecture

This document is one of three. It describes the Operational Concept (OpsCon) for a generic space exploration communication architecture. The purpose of this particular document is to identify communication flows and data types. Two other documents accompany this document, a security policy profile and a communication architecture document. The operational concepts should be read first followed by the security policy profile and then the architecture document. The overall goal is to design a generic space exploration communication network architecture that is affordable, deployable, maintainable, securable, evolvable, reliable, and adaptable. The architecture should also require limited reconfiguration throughout system development and deployment. System deployment includes: subsystem development in a factory setting, system integration in a laboratory setting, launch preparation, launch, and deployment and operation in space.

networking↗

High Flux Isotope Reactor Low-Enriched Uranium High Density Silicide Fuel Preliminary Design Update: System Transient Analysis

As a part of conversion efforts from highly enriched uranium (HEU) to low-enriched uranium (LEU) fuel under direction of the National Nuclear Security Administration of the U.S. Department of Energy, multiple proposed designs of the High Flux Isotope Reactor (HFIR) have been created and assessed regarding reactor physics performance metrics, including designs utilizing uranium silicide dispersion fuel (U3Si2-Al). This report updates the previous analyses that evaluated the nuclear safety performance of LEU fuel designs with respect to selected accident events from the HFIR Safety Analysis Report (SAR). Both the Low Density (LD) and High Density (HD) Optimized designs’ reactivity initiated accident fuel performance improved relative to the HEU fuel, attributed to greater 238 U negative Doppler feedback. However, the thermal margins for primary coolant system accidents were reduced with some acceptance criteria unable to be met. The need to resolve reduced thermal margin, open modeling items, and unresolved assumptions was identified.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗