Search NASA⌕ Search

SEARCH · Search NASA

Results for “Secure by Design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 217 records · Page 12

Payload Performance of Third Generation TDRS and Future Services

NASA has accepted two of the 3rd generation Tracking and Data Relay Satellites, TDRS K, L, and M, designed and built by Boeing Defense, Space & Security (DSS). TDRS K, L, and M provide S-band Multiple Access (MA) service and S-band, Ku-band and Ka-band Single Access (SA) services to near Earth orbiting satellites. The TDRS KLM satellites offer improved services relative to the 1st generation TDRS spacecraft, such as: an enhanced MA service featuring increased EIRPs and G/T; and Ka-band SA capability which provides a 225 and 650 MHz return service (customer-to-TDRS direction) bandwidth and a 50 MHz forward service (TDRS-to-customer direction) bandwidth. MA services are provided through a 15 element forward phased array that forms up to two beams with onboard active beamforming and a 32 element return phased array supported by ground-based beamforming. SA services are provided through two 4.6m tri-band reflector antennas which support program track pointing and autotrack pointing. Prior to NASAs acceptance of the satellites, payload on-orbit testing was performed on each satellite to determine on-orbit compliance with design requirements. Performance parameters evaluated include: EIRP, G/T, antenna gain patterns, SA antenna autotrack performance, and radiometric tracking performance. On-orbit antenna calibration and pointing optimization was also performed on the MA and SA antennas including 24 hour duration tests to characterize and calibrate out diurnal effects. Bit-Error-Rate (BER) tests were performed to evaluate the end-to-end link BER performance of service through a TDRS K and L spacecraft. The TDRS M is planned to be launched in August 2017. This paper summarizes the results of the TDRS KL communications payload on-orbit performance verification and end-to-end service characterization and compares the results with the performance of the 2nd generation TDRS J. The paper also provides a high-level overview of an optical communications application that will augment the data rates supported by the Space Network.

RF↗

Payload Performance of TDRS KL and Future Services

NASA has accepted two of the 3nd generation Tracking and Data Relay Satellites, TDRS K, L, and M, designed and built by Boeing Defense, Space Security (DSS). TDRS K, L, and M provide S-band Multiple Access (MA) service and S-band, Ku-band and Ka-band Single Access (SA) services to near Earth orbiting satellites. The TDRS KLM satellites offer improved services relative to the 1st generation TDRS spacecraft, such as: an enhanced MA service featuring increased EIRPs and GT; and Ka-band SA capability which provides a 225 and 650 MHz return service (customer-to-TDRS direction) bandwidth and a 50 MHz forward service (TDRS-to-customer direction) bandwidth. MA services are provided through a 15 element forward phased array that forms up to two beams with onboard active beamforming and a 32 element return phased array supported by ground-based beamforming. SA services are provided through two 4.6m tri-band reflector antennas which support program track pointing and autotrack pointing. Prior to NASAs acceptance of the satellites, payload on-orbit testing was performed on each satellite to determine on-orbit compliance with design requirements. Performance parameters evaluated include: EIRP, GT, antenna gain patterns, SA antenna autotrack performance, and radiometric tracking performance. On-orbit antenna calibration and pointing optimization was also performed on the MA and SA antennas including 24 hour duration tests to characterize and calibrate out diurnal effects. Bit-Error-Rate (BER) tests were performed to evaluate the end-to-end link BER performance of service through a TDRS K and L spacecraft. The TDRS M is planned to be launched in August 2017. This paper summarizes the results of the TDRS KL communications payload on-orbit performance verification and end-to-end service characterization and compares the results with the performance of the 2nd generation TDRS J. The paper also provides a high-level overview of an optical communications application that will augment the data rates supported by the Space Network.

Laser↗

Small Fast Spectrum Reactor Designs Suitable for Direct Nuclear Thermal Propulsion

Advancement of U.S. scientific, security, and economic interests through a robust space exploration program requires high performance propulsion systems to support a variety of robotic and crewed missions beyond low Earth orbit. Past studies, in particular those in support of the Space Exploration Initiative (SEI), have shown nuclear thermal propulsion systems provide superior performance for high mass high propulsive delta-V missions. The recent NASA Design Reference Architecture (DRA) 5.0 Study re-examined mission, payload, and transportation system requirements for a human Mars landing mission in the post-2030 timeframe. Nuclear thermal propulsion was again identified as the preferred in-space transportation system. A common nuclear thermal propulsion stage with three 25,000-lbf thrust engines was used for all primary mission maneuvers. Moderately lower thrust engines may also have important roles. In particular, lower thrust engine designs demonstrating the critical technologies that are directly extensible to other thrust levels are attractive from a ground testing perspective. An extensive nuclear thermal rocket technology development effort was conducted from 1955-1973 under the Rover/NERVA Program. Both graphite and refractory metal alloy fuel types were pursued. Reactors and engines employing graphite based fuels were designed, built and ground tested. A number of fast spectrum reactor and engine designs employing refractory metal alloy fuel types were proposed and designed, but none were built. The Small Nuclear Rocket Engine (SNRE) was the last engine design studied by the Los Alamos National Laboratory during the program. At the time, this engine was a state-of-the-art graphite based fuel design incorporating lessons learned from the very successful technology development program. The SNRE was a nominal 16,000-lbf thrust engine originally intended for unmanned applications with relatively short engine operations and the engine and stage design were constrained to fit within the payload volume of the then planned space shuttle. The SNRE core design utilized hexagonal fuel elements and hexagonal structural support elements. The total number of elements can be varied to achieve engine designs of higher or lower thrust levels. Some variation in the ratio of fuel elements to structural elements is also possible. Options for SNRE-based engine designs in the 25,000-lbf thrust range were described in a recent (2010) Joint Propulsion Conference paper. The reported designs met or exceeded the performance characteristics baselined in the DRA 5.0 Study. Lower thrust SNRE-based designs were also described in a recent (2011) Joint Propulsion Conference paper. Recent activities have included parallel evaluation and design efforts on fast spectrum engines employing refractory metal alloy fuels. These efforts include evaluation of both heritage designs from the Argonne National Laboratory (ANL) and General Electric Company GE-710 Programs as well as more recent designs. Results are presented for a number of not-yet optimized fast spectrum engine options.

Schnitzler, Bruce G.↗

Improving Security of Ground System Software

An estimated 84% of all security breaches are application-related, not firewall violations. To what extent is your organization focused on addressing security issues in its software? Software plays a critical role in mission success, and software similarly plays a role in mission security. However, software can introduce vulnerabilities to the system, such as use of a COTS product that has a backdoor, or a hole in the security of the system deliberately left in place by designers or maintainers. The motivations for such holes are not always sinister, but can provide a means for malicious intrusion into the mission. Students will learn an approach to securing ground software within the context of federal information systems. Federal requirements, coding standards, tool usage will be discussed as part of the solution to securing software.

Bailey, Brandon↗

Automated Theorem Proving in High-Quality Software Design

The amount and complexity of software developed during the last few years has increased tremendously. In particular, programs are being used more and more in embedded systems (from car-brakes to plant-control). Many of these applications are safety-relevant, i.e. a malfunction of hardware or software can cause severe damage or loss. Tremendous risks are typically present in the area of aviation, (nuclear) power plants or (chemical) plant control. Here, even small problems can lead to thousands of casualties and huge financial losses. Large financial risks also exist when computer systems are used in the area of telecommunication (telephone, electronic commerce) or space exploration. Computer applications in this area are not only subject to safety considerations, but also security issues are important. All these systems must be designed and developed to guarantee high quality with respect to safety and security. Even in an industrial setting which is (or at least should be) aware of the high requirements in Software Engineering, many incidents occur. For example, the Warshaw Airbus crash, was caused by an incomplete requirements specification. Uncontrolled reuse of an Ariane 4 software module was the reason for the Ariane 5 disaster. Some recent incidents in the telecommunication area, like illegal "cloning" of smart-cards of D2GSM handies, or the extraction of (secret) passwords from German T-online users show that also in this area serious flaws can happen. Due to the inherent complexity of computer systems, most authors claim that only a rigorous application of formal methods in all stages of the software life cycle can ensure high quality of the software and lead to real safe and secure systems. In this paper, we will have a look, in how far automated theorem proving can contribute to a more widespread application of formal methods and their tools, and what automated theorem provers (ATPs) must provide in order to be useful.

Schumann, Johann↗

Investigation of mechanochemical interactions of hydrogen with earth materials in a subsurface gas storage

The goal of this project is to investigate the molecular interactions of H 2 with earth materials (EMs) that may potentially affect economics and safety of H 2 geological storage (HGS). We investigated (1) the H 2 intercalation into interlayers of phyllosilicates, (2) the competitive adsorption of H 2 /CH 4 onto porous materials, and (3) solubility of H 2 in interfacial and confined hydrocarbons. Our results indicate that (i) H 2 intercalation into hydrated interlayers is thermodynamically unfavorable and H 2 solubility in hydrated clay interlayers is in the same order of magnitude as that in bulk water, (ii) CH 4 outcompetes H 2 in adsorption onto kerogen, due to stronger CH 4 -kerogen interactions than H 2 -kerogen interactions, (iii) H 2 tends to dissolve more in oil than in water, and the introduction of CO 2 as a cushion gas reduces H 2 partitioning near the kaolinite surfaces. The outcomes provide foundational knowledge for preparing the USA for future storage site selection and storage system design, supporting DOE missions in clean and secured energy.

08 HYDROGEN↗

VA EDH Advanced Software Pipeline Framework Report: Enhancing Automation and Scalability

The VA Environmental Determinants of Health (EDH) Advanced Software Pipeline Framework is designed to enhance the efficiency, scalability, and security of geospatial data processing workflows. This framework integrates modern data orchestration and containerization technologies, including Prefect for workflow automation, Docker for containerization, and PostgreSQL/PostGIS for geospatial data storage and analysis. It ensures standardized, reproducible, and automated data processing, supporting VA objectives related to substance use risk assessment and recovery research. The pipeline addresses key scalability and performance challenges through horizontal and vertical scaling, high-performance computing (HPC) integration, parallel processing, task caching, and dynamic resource allocation. These optimizations improve throughput and reduce latency, allowing the system to efficiently manage large and complex datasets. Additionally, security and compliance measures—such as data encryption (SSL), Role-Based Access Control (RBAC), and adherence to GDPR and HIPAA standards—safeguard sensitive information throughout data transmission and storage. A key implementation of this framework includes the automation of shelter list geolocation workflows, ensuring that up-to-date data is readily available for VA decision-making. Lessons learned from this project include the transition from in-memory processing to incremental storage writes, improving resource management and reliability. Future enhancements aim to expand automation, integrate AI-driven anomaly detection, and incorporate high-performance computing resources. This framework provides a scalable, secure, and adaptable solution for managing geospatial datasets, reinforcing the VA’s ability to support clinical and strategic initiatives through data-driven decision-making.

97 MATHEMATICS AND COMPUTING↗

Engineering flight evaluation report

The primary objective was to determine if the two-segment profile equipment, and operational procedures as defined by the B-727 Simulation Evaluation are operationally sound under all flight conditions expected to be encountered in line service. The evaluation was divided into the following areas: (1) to verify that the two-segment system operates as it was designed; (2) to conduct sufficient tests to secure a supplemental type certificate for line operation of the system; (3) to evaluate the normal operation of the equipment and procedures; (4) to evaluate the need for an autothrottle system for two-segment approaches; (5) to investigate abnormal operation of the equipment and procedures, including abused approaches and malfunctions of airborne and ground components; (6) to determine the accuracy and ease of flying the two-segment approach; (7) to determine the improvement in ground noise levels; and (8) to develop a guest pilot flight test syllabus.

Morrison, J. A.↗

Laboratory glassware rack for seismic safety

A rack for laboratory bottles and jars for chemicals and medicines has been designed to provide the maximum strength and security to the glassware in the event of a significant earthquake. The rack preferably is rectangular and may be made of a variety of chemically resistant materials including polypropylene, polycarbonate, and stainless steel. It comprises a first plurality of parallel vertical walls, and a second plurality of parallel vertical walls, perpendicular to the first. These intersecting vertical walls comprise a self-supporting structure without a bottom which sits on four legs. The top surface of the rack is formed by the top edges of all the vertical walls, which are not parallel but are skewed in three dimensions. These top edges form a grid matrix having a number of intersections of the vertical walls which define a number of rectangular compartments having varying widths and lengths and varying heights.

Cohen, M. M.↗

Making Complex Electrically Conductive Patterns on Cloth

A method for automated fabrication of flexible, electrically conductive patterns on cloth substrates has been demonstrated. Products developed using this method, or related prior methods, are instances of a technology known as 'e-textiles,' in which electrically conductive patterns ar formed in, and on, textiles. For many applications, including high-speed digital circuits, antennas, and radio frequency (RF) circuits, an e-textile method should be capable of providing high surface conductivity, tight tolerances for control of characteristic impedances, and geometrically complex conductive patterns. Unlike prior methods, the present method satisfies all three of these criteria. Typical patterns can include such circuit structures as RF transmission lines, antennas, filters, and other conductive patterns equivalent to those of conventional printed circuits. The present method overcomes the limitations of the prior methods for forming the equivalent of printed circuits on cloth. A typical fabrication process according to the present method involves selecting the appropriate conductive and non-conductive fabric layers to build the e-textile circuit. The present method uses commercially available woven conductive cloth with established surface conductivity specifications. Dielectric constant, loss tangent, and thickness are some of the parameters to be considered for the non-conductive fabric layers. The circuit design of the conductive woven fabric is secured onto a non-conductive fabric layer using sewing, embroidery, and/or adhesive means. The portion of the conductive fabric that is not part of the circuit is next cut from the desired circuit using an automated machine such as a printed-circuit-board milling machine or a laser cutting machine. Fiducials can be used to align the circuit and the cutting machine. Multilayer circuits can be built starting with the inner layer and using conductive thread to make electrical connections between layers.

Chu, Andrew↗

Small Autonomous Air/Sea System Concepts for Coast Guard Missions

A number of small autonomous air/sea system concepts are outlined in this paper that support and enhance U.S. Coast Guard missions. These concepts draw significantly upon technology investments made by NASA in the area of uninhabited aerial vehicles and robotic/intelligent systems. Such concepts should be considered notional elements of a greater as-yet-not-defined robotic system-of-systems designed to enable unparalleled maritime safety and security.

Young, Larry A.↗

Ultra-Low-Noise W-Band MMIC Detector Modules

A monolithic microwave integrated circuit (MMIC) receiver can be used as a building block for next-generation radio astronomy instruments that are scalable to hundreds or thousands of pixels. W-band (75-110 GHz) low-noise receivers are needed for radio astronomy interferometers and spectrometers, and can be used in missile radar and security imagers. These receivers need to be designed to be mass-producible to increase the sensitivity of the instrument. This innovation is a prototyped single-sideband MMIC receiver that has all the receiver front-end functionality in one small and planar module. The planar module is easy to assemble in volume and does not require tuning of individual receivers. This makes this design low-cost in large volumes.

Gaier, Todd C.↗

OSIRIS-REx Touch-and-Go (TAG) Mission Design for Asteroid Sample Collection

The Origins Spectral Interpretation Resource Identification Security Regolith Explorer (OSIRIS-REx) mission is a NASA New Frontiers mission launching in September 2016 to rendezvous with the near-Earth asteroid Bennu in October 2018. After several months of proximity operations to characterize the asteroid, OSIRIS-REx flies a Touch-And-Go (TAG) trajectory to the asteroid's surface to collect at least 60 g of pristine regolith sample for Earth return. This paper provides mission and flight system overviews, with more details on the TAG mission design and key events that occur to safely and successfully collect the sample. An overview of the navigation performed relative to a chosen sample site, along with the maneuvers to reach the desired site is described. Safety monitoring during descent is performed with onboard sensors providing an option to abort, troubleshoot, and try again if necessary. Sample collection occurs using a collection device at the end of an articulating robotic arm during a brief five second contact period, while a constant force spring mechanism in the arm assists to rebound the spacecraft away from the surface. Finally, the sample is measured quantitatively utilizing the law of conservation of angular momentum, along with qualitative data from imagery of the sampling device. Upon sample mass verification, the arm places the sample into the Stardust-heritage Sample Return Capsule (SRC) for return to Earth in September 2023.

OSIRIS-REX TOUCH-AND-GO (TAG) MISSION DESIGN FOR A↗

Securing Small Modular Reactors in Urban Environments

Current small modular reactor (SMR) deployment use cases consider both rural and urban deployments, depending on the operational in-country needs for clean and reliable sources of energy. Many studies have been conducted analyzing security in rural and remote deployment locations, but this study looks at the physical security implications of an SMR placed in an urban environment and its uses for electricity production, district heating, and process heating. SMRs used for electricity production, district heating, and process heating may be key sources of both energy infrastructure and commercial infrastructure within a city and a State. As a result, long-term shutdowns could have a serious impact on a State’s overall energy or commercial production. Therefore, operators may consider further security applications to protect an SMR plant from physical attacks against both radiological sabotage and sabotage acts that could result in the SMR facility being offline for a significant amount of time. In this study, the team designed and analyzed a physical protection system (PPS) for securing an urban SMR facility against acts of radiological sabotage and sabotage acts that could disrupt the facility’s long-term operation. Additionally, this work analyzed the nuanced security issues related to siting an SMR near an urban environment (versus in a rural environment). The result of these analyses includes recommendations for PPSs for urban SMR facilities used for energy production, district heating, and process heating.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Automation of Vulnerability and Patch Management: Information Extraction, Association, and Optimization

Vulnerability and patch management is an integral part of a robust cybersecurity program, yet it grows increasingly complex due to the sheer amount of data that must be analyzed. Particularly in Operational Technology (OT) environments, analysis must be done manually because of the lack of automated solutions. Additionally, there are many steps in this process, from the initial discovery of the vulnerability to the implementation of its remediation, and each step in the process requires different data in order to be performed effectively. In this work, we provide approaches and strategies to assist operators in industrial or OT environments throughout the vulnerability management cycle. Security advisories provide key information about mitigation strategies, or actions that can be taken when a patch is unavailable or cannot be installed. Details of these strategies are not shared in public vulnerability databases and must be found manually. We approach this problem by designing a solution to automatically identify that information within vendor security advisories and retrieve it for operator use. We start with an approach that requires domain-specific knowledge of certain frequently-seen reference websites. Next, an approach that can work on an arbitrary website but relies on certain keywords. Finally, an approach that uses Natural Language Processing (NLP) methods and does not require specific knowledge or keywords. Each of these approaches is more general than its predecessor; we demonstrate high accuracy for all approaches Advisories also often contain details of affected products in non-standard or natural language formats. While this information can be easily understood when read by an operator, the non-standard format acts as a barrier to effective automation. We provide an approach for the first step in this process: identifying vendors in security advisories and mapping them to a standard framework for representing digital assets and software products. We evaluate five established string similarity algorithms, plus one of our own design that combines string similarity and information theory, on the task of mapping vendors to their corresponding entries in the Common Platform Enumeration (CPE) repository. Our results show that our proposed metric outperforms all others. Due to the constraints on time, finances, and personnel for organizations, Large Language Models (LLMs) may seem like attractive opportunities for security operators to speed up information gathering; however, it is still not clear whether LLMs can handle vulnerability management tasks well. To answer this question, we perform an empirical study of LLMs’ ability to provide consistent, accurate information about vulnerabilities in order to guide organizations in their adoption of LLMs. We observe poor performance for all models tested, suggesting that these models are not well-suited to the consistent retrieval of accurate vulnerability information. Finally, once vulnerabilities have been identified and any additional information has been obtained, operators must decide which remediation actions to implement based on their available resources. This already-complex problem becomes even more so when we consider that a vulnerability may have multiple avenues for remediation. We formulate this scenario as two knapsack problems and provide solutions, which we then compare against several existing strategies for vulnerability prioritization seen in real operational environments.

McClanahan, Kylie↗

Software and System Health Management with R2U2

R2U2 (Realizable, Responsive, Unobtrusive Unit) is a hardware-supported tool and framework for the real-time system and software health management of cyber-physical systems. R2U2 continuously monitors properties about safety, performance, and security of the vehicle and can perform diagnostic reasoning. Efficient observers for past-time and future-time Metric Temporal Logic, reasoners for Bayesian Networks, and model-based prognostics algorithms are major components of R2U2. Their combination makes it possible to design powerful models for system runtime monitoring, diagnostics, software health management, prognostics, and security monitoring. The R2U2 monitoring engine is designed for minimal runtime overhead and is available as Simulink block or as a software component for integration into the flight software stack, and enables R2U2 to monitor complex cyber-physical systems without any instrumentation of the flight software. In this presentation, we give an overview of R2U2 architecture and reasoning algorithms, present its features, and give a life demo of the tool.

Schumann, Johann↗

Security Policy for a Generic Space Exploration Communication Network Architecture

This document is one of three. It describes various security mechanisms and a security policy profile for a generic space-based communication architecture. Two other documents accompany this document- an Operations Concept (OpsCon) and a communication architecture document. The OpsCon should be read first followed by the security policy profile described by this document and then the architecture document. The overall goal is to design a generic space exploration communication network architecture that is affordable, deployable, maintainable, securable, evolvable, reliable, and adaptable. The architecture should also require limited reconfiguration throughout system development and deployment. System deployment includes subsystem development in a factory setting, system integration in a laboratory setting, launch preparation, launch, and deployment and operation in space.

networking↗

ARCADE Analysis Methods & Validation Pathway

The Advanced Reactor Cyber Analysis and Development Environment (ARCADE) provides an automated analysis system which supports risk-informed performance based (RIPB) evaluations of nuclear control systems. Every possible cyber threat which could lead to consequence is identified by simulating the unsafe control action sequences which transform digital harm into physical harm. Eliminating the simulation of complex digital cyber attack chains cuts out unnecessary computational overhead and focuses directly on the physics of cyber-physical attacks. This focus enables designers to make informed decisions which can entirely eliminate categories of cyber threats against advanced reactors through the physical nature of the plant design. This narrowing of cyber threat against nuclear power plants through the physics of the system is intended to make any remaining threat management and cost efficient. This is the goal of the Tiered Cyber Analysis (TCA) outlined in NRC Draft Regulation Guide (RG) 5.96, which provides a RIPB cybersecurity approach for new reactors. ARCADE has been custom developed to meet the demands of the rigorous analysis required in Tier 1 of the TCA, which forms the foundation of the TCA process. Currently, ARCADE is still under development, but has made significant leaps in capability. A pilot analysis on the opensource Asherah simulator was performed which demonstrated key functionality goals. The next stage of ARCADE development involves improvements to the applications which support the analysis system, and enabling the analysis system to utilize the full suite of unsafe control action simulations. Since the analysis method’s core functions are complete, validation of the analysis method will be started concurrent to the next development stages. The automated analysis ARCADE will provide can radically change the cybersecurity design process for advanced reactors, reducing the cost of security implementation while enhancing cyber resilience. The pathway for ARCADE’s development to this goal has become much clearer. The majority of technical hurdles have been cleared, and the remaining development needs have been solidified. ARCADE is now capable of assisting the advanced reactor design process and directly support advanced reactor industry RIPB practices.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗