Search NASA⌕ Search

SEARCH · Search NASA

Results for “Secure by Design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 253 records · Page 14

Secure Intra-Body Wireless Communications (SIWiC) System Project

SIWiC System is a project to investigate, design and implement future wireless networks of implantable sensors in the body. This futuristic project is designed to make use of the emerging and yet-to-emerge technologies, including ultra-wide band (UWB) for wireless communications, smart implantable sensors, ultra low power networking protocols, security and privacy for bandwidth and power deficient devices and quantum computing. Progress in each of these fronts is hindered by the needs of breakthrough. But, as we will see in this paper, these major challenges are being met or will be met in near future. SIWiC system is a network of in-situ wireless devices that are implanted to coordinate sensed data inside the body, such as symptoms monitoring collected internally, or biometric data collected of an outside object from within the intra-body network. One node has the capability of communicating outside the body to send data or alarm to a relevant authority, e.g., a remote physician.

Ahmad, Aftab↗

Rotational Millimeter-Wave Shoe Scanner Using the Discrete Fourier Transform for Backprojection-Based Image Reconstruction

An active 3D microwave / millimeter-wave shoe scanner was previously developed at the Pacific Northwest National Laboratory (PNNL) using two linear arrays scanned over a rectilinear aperture. The radar system chirps a frequency sweep from 10-40 GHz. These frequencies allow imaging through optically opaque material such as leather, rubber, plastics, and other dielectrics. The system was designed to detect concealed items in the soles of shoes while allowing people to leave their shoes on through a security checkpoint. To shrink the footprint of the system, a new iteration of the design has been developed that scans the two linear arrays over a circular aperture. This new footprint opens the possibility of it being installed in the floor of a cylindrical millimeter-wave body scanner. The backprojection-based multilayer dielectric image reconstruction developed at PNNL can easily handle arbitrary spatial sampling, accommodating the new rotational shoe scanner design. Commonly, the fast Fourier transform (FFT) is used to efficiently compute the range response from the data collected by the system as a preprocessing step to the backprojection algorithm. It was found that converting to range using the discrete Fourier transform (DFT) directly has some advantages over the FFT. For example, nonlinear and non-uniform frequency sweeps can easily be compensated for during the computation of the DFT and only the range bins of interest need to be computed and their spacing can be chosen arbitrarily. Because the range conversion step of the image reconstruction is the fastest part of the process there is very little speed penalty for using the DFT over the FFT and it can even increase the speed of image reconstruction when the ranges of interest are fewer than the total span that is calculated in the FFT.

Millimeter-wave imaging, microwave imaging, shoe s↗

Toward Synthesis, Analysis, and Certification of Security Protocols

Implemented security protocols are basically pieces of software which are used to (a) authenticate the other communication partners, (b) establish a secure communication channel between them (using insecure communication media), and (c) transfer data between the communication partners in such a way that these data only available to the desired receiver, but not to anyone else. Such an implementation usually consists of the following components: the protocol-engine, which controls in which sequence the messages of the protocol are sent over the network, and which controls the assembly/disassembly and processing (e.g., decryption) of the data. the cryptographic routines to actually encrypt or decrypt the data (using given keys), and t,he interface to the operating system and to the application. For a correct working of such a security protocol, all of these components must work flawlessly. Many formal-methods based techniques for the analysis of a security protocols have been developed. They range from using specific logics (e.g.: BAN-logic [4], or higher order logics [12] to model checking [2] approaches. In each approach, the analysis tries to prove that no (or at least not a modeled intruder) can get access to secret data. Otherwise, a scenario illustrating the &tack may be produced. Despite the seeming simplicity of security protocols ("only" a few messages are sent between the protocol partners in order to ensure a secure communication), many flaws have been detected. Unfortunately, even a perfect protocol engine does not guarantee flawless working of a security protocol, as incidents show. Many break-ins and security vulnerabilities are caused by exploiting errors in the implementation of the protocol engine or the underlying operating system. Attacks using buffer-overflows are a very common class of such attacks. Errors in the implementation of exception or error handling can open up additional vulnerabilities. For example, on a website with a log-in screen: multiple tries with invalid passwords caused the expected error message (too many retries). but let the user nevertheless pass. Finally, security can be compromised by silly implementation bugs or design decisions. In a commercial VPN software, all calls to the encryption routines were incidentally replaced by stubs, probably during factory testing. The product worked nicely. and the error (an open VPN) would have gone undetected, if a team member had not inspected the low-level traffic out of curiosity. Also, the use secret proprietary encryption routines can backfire, because such algorithms often exhibit weaknesses which can be exploited easily (see e.g., DVD encoding). Summarizing, there is large number of possibilities to make errors which can compromise the security of a protocol. In today s world with short time-to-market and the use of security protocols in open and hostile networks for safety-critical applications (e.g., power or air-traffic control), such slips could lead to catastrophic situations. Thus, formal methods and automatic reasoning techniques should not be used just for the formal proof of absence of an attack, but they ought to be used to provide an end-to-end tool-supported framework for security software. With such an approach all required artifacts (code, documentation, test cases) , formal analyses, and reliable certification will be generated automatically, given a single, high level specification. By a combination of program synthesis, formal protocol analysis, certification; and proof-carrying code, this goal is within practical reach, since all the important technologies for such an approach actually exist and only need to be assembled in the right way.

Schumann, Johann↗

Restructuring and Optimizing Reactor Building Lifting Processes & Designing a Solution for an Overhead Door Handling Forklift Attachment

This poster presents two innovative projects aimed at enhancing operational efficiency and safety at the Advanced Test Reactor (ATR) Complex. The first project focuses on restructuring the existing lift book used for hoisting operations within the ATR Reactor Building. The current lift book, a cumbersome 150+ page document, is being transformed into a more efficient format using charts that allow for quick identification of maximum lift heights based on object footprint and weight. This new method also considers various parameters such as floor integrity and reactor status, dividing entries into four distinct charts to improve usability and safety during lifts. The second project involves designing a specialized forklift attachment for handling an overhead door at the ATR Reactor Building. The attachment is engineered to securely lift and lower a 1200lb, 14ft long door, ensuring safe replacement operations. The design process included research on forklift attachment codes, modeling in Autodesk Inventor, and testing through Finite Element Analysis (FEA) and hand calculations to confirm the attachment's structural integrity. Future work includes completing detailed drawings and an Engineering Calculations Analysis and Review (ECAR) document to proceed with manufacturing and assembly. Together, these projects demonstrate a commitment to optimizing reactor building operations through innovative engineering solutions and safety considerations.

42 - ENGINEERING↗

Technology Development, Implementation, and Assessment: K-16 Pre-Service, In-Service, and Distance Learning Initiatives

This summer 22 kindergarten through 8th grade teachers attended a 3-week Teacher Enhancement Institute (TEI) at NASA Langley Research Center. TEI is funded by NASA Education Division and is a collaborative effort between NASA Langley's Office of Education and Christopher Newport University. Selected teacher teams were drawn from Langley's 5-state precollege service region, which includes Kentucky, North Carolina, South Carolina, Virginia, and West Virginia. The goal of TEI was for teachers to learn aeronautics and the broad application of science and technology through a problem-based learning (PBL) strategy. PBL is an instructional method using a real world problem, also known as an ill-structured problem, as the context for an in-depth investigation. Most real life problems are ill-structured, as are all the really important social, political and scientific problems. The teachers were immediately immersed in an ill-structured problem to design a communication strategy for the White House Commission on Aviation Safety and Security to educate and disseminate aviation information to the general public. Specifically, the communication strategy was to focus on aeronautics principles, technology and design associated with US general aviation revitalization and aviation safety programs. The presented problem addressed NASA's strategic outcome to widely communicate the content, relevancy and excitement of its missions and discoveries to the general population. Further, the PBL scenario addressed the technological challenges being taken up by NASA to revolutionize air travel and the way in which aircraft are designed, built, and operated. It also addressed getting people and freight safely and efficiently to any location in the world at a reasonable cost. With a "real" need-to-know problem facing them, the teachers set out to gather information and to better understand the problem using inquiry-based and scientific methods. The learning in this aeronautics scenario was driven by the direction taken by participants. With the support of the TEI faculty, the teachers quickly identified NASA Langley researchers that served as consultants to help solve the problem. To achieve their goal, the teacher teams developed lesson plans for elementary and middle school students, wrote a newspaper, published a brochure to educate the general public, constructed games for children of all ages, and produced a video. As a second problem, the TEI participants will design their own aeronautic lesson plan and immerse their 1997-98 school year students in the problem. The problem is for the students "to create a traveling hands-on, minds-on aeronautics museum exhibit created for children by children." As a culminating activity, the Virginia Air and Space Center in Hampton, VA, will set up a special display of the exhibits in the Summer 1998. The TEI faculty will visit each TEI teacher's classroom during the academic school year to observe the implementation of the unit. In addition to the classroom observations, electronic follow-up sessions will be conducted during the school year to support the teachers' efforts in developing their PBL units to integrate technology in math and science instruction. These sessions eill be conducted using the Internet. Teachers will be connected through a chat-line to share ideas, ask questions, and generate solutions.

Petersen, Richard↗

GLobal Integrated Design Environment

The GLobal Integrated Design Environment (GLIDE) is a collaborative engineering application built to resolve the design session issues of real-time passing of data between multiple discipline experts in a collaborative environment. Utilizing Web protocols and multiple programming languages, GLIDE allows engineers to use the applications to which they are accustomed in this case, Excel to send and receive datasets via the Internet to a database-driven Web server. Traditionally, a collaborative design session consists of one or more engineers representing each discipline meeting together in a single location. The discipline leads exchange parameters and iterate through their respective processes to converge on an acceptable dataset. In cases in which the engineers are unable to meet, their parameters are passed via e-mail, telephone, facsimile, or even postal mail. The result of this slow process of data exchange would elongate a design session to weeks or even months. While the iterative process remains in place, software can now exchange parameters securely and efficiently, while at the same time allowing for much more information about a design session to be made available. GLIDE is written in a compilation of several programming languages, including REALbasic, PHP, and Microsoft Visual Basic. GLIDE client installers are available to download for both Microsoft Windows and Macintosh systems. The GLIDE client software is compatible with Microsoft Excel 2000 or later on Windows systems, and with Microsoft Excel X or later on Macintosh systems. GLIDE follows the Client-Server paradigm, transferring encrypted and compressed data via standard Web protocols. Currently, the engineers use Excel as a front end to the GLIDE Client, as many of their custom tools run in Excel.

Kunkel, Matthew↗

Spinoff 2012

Topics covered include: Water Treatment Technologies Inspire Healthy Beverages; Dietary Formulas Fortify Antioxidant Supplements; Rovers Pave the Way for Hospital Robots; Dry Electrodes Facilitate Remote Health Monitoring; Telescope Innovations Improve Speed, Accuracy of Eye Surgery; Superconductors Enable Lower Cost MRI Systems; Anti-Icing Formulas Prevent Train Delays; Shuttle Repair Tools Automate Vehicle Maintenance; Pressure-Sensitive Paints Advance Rotorcraft Design Testing; Speech Recognition Interfaces Improve Flight Safety; Polymers Advance Heat Management Materials for Vehicles; Wireless Sensors Pinpoint Rotorcraft Troubles; Ultrasonic Detectors Safely Identify Dangerous, Costly Leaks; Detectors Ensure Function, Safety of Aircraft Wiring; Emergency Systems Save Tens of Thousands of Lives; Oxygen Assessments Ensure Safer Medical Devices; Collaborative Platforms Aid Emergency Decision Making; Space-Inspired Trailers Encourage Exploration on Earth; Ultra-Thin Coatings Beautify Art; Spacesuit Materials Add Comfort to Undergarments; Gigapixel Images Connect Sports Teams with Fans; Satellite Maps Deliver More Realistic Gaming; Elemental Scanning Devices Authenticate Works of Art; Microradiometers Reveal Ocean Health, Climate Change; Sensors Enable Plants to Text Message Farmers; Efficient Cells Cut the Cost of Solar Power; Shuttle Topography Data Inform Solar Power Analysis; Photocatalytic Solutions Create Self-Cleaning Surfaces; Concentrators Enhance Solar Power Systems; Innovative Coatings Potentially Lower Facility Maintenance Costs; Simulation Packages Expand Aircraft Design Options; Web Solutions Inspire Cloud Computing Software; Behavior Prediction Tools Strengthen Nanoelectronics; Power Converters Secure Electronics in Harsh Environments; Diagnostics Tools Identify Faults Prior to Failure; Archiving Innovations Preserve Essential Historical Records; Meter Designs Reduce Operation Costs for Industry; Commercial Platforms Allow Affordable Space Research; Fiber Optics Deliver Real-Time Structural Monitoring; Camera Systems Rapidly Scan Large Structures; Terahertz Lasers Reveal Information for 3D Images; Thin Films Protect Electronics from Heat and Radiation; Interferometers Sharpen Measurements for Better Telescopes; and Vision Systems Illuminate Industrial Processes.

Source record↗

Mechanical Design of the PIP-II ORBUMP Pulsed Dipole Magnet

The Proton Improvement Plan II (PIP-II) project is a vital upgrade to the Fermilab accelerator complex. The magnet pulse rate of the PIP-II Injection system requires an increase from the current rate of 15 Hz to 20 Hz as well as a roughly 30% increase in the magnetic field of the new Orbital Bump (ORBUMP) pulsed dipole magnets in the Booster. Here, the ORBUMP magnet mechanical design is presented in this paper. The ORBUMP magnet is secured in a vacuum box and the core is made up of 0.127 mm thick, low carbon steel laminations with a C-5 inorganic magnesium phosphate coating. The core is clamped using external tie bars welded to the core end plates. ANSYS Finite Element Analysis (FEA) was used to evaluate the clamping design to minimize the deflection of the core post welding of the tie bars. The water-cooled, single turn coil, which shapes the magnetic field by acting as the pole tips, is critical for the integrated field homogeneity. The coil manufacturing tolerances and fabrication techniques were evaluated to ensure the magnetic properties of the magnet could be obtained. The coil is electrically isolated from the core using virgin Polyether ether ketone (PEEK) insulating material in the gap. An investigation into the high voltage performance of the virgin PEEK insulator was conducted via partial discharge testing using a 1:1 scale sample.

Karas, D. [Fermi National Accelerator Laboratory (↗

Spaceflight Operations Services Grid (SOSG)

In an effort to adapt existing space flight operations services to new emerging Grid technologies we are developing a Grid-based prototype space flight operations Grid. This prototype is based on the operational services being provided to the International Space Station's Payload operations located at the Marshall Space Flight Center, Alabama. The prototype services will be Grid or Web enabled and provided to four user communities through portal technology. Users will have the opportunity to assess the value and feasibility of Grid technologies to their specific areas or disciplines. In this presentation descriptions of the prototype development, User-based services, Grid-based services and status of the project will be presented. Expected benefits, findings and observations (if any) to date will also be discussed. The focus of the presentation will be on the project in general, status to date and future plans. The End-use services to be included in the prototype are voice, video, telemetry, commanding, collaboration tools and visualization among others. Security is addressed throughout the project and is being designed into the Grid technologies and standards development. The project is divided into three phases. Phase One establishes the baseline User-based services required for space flight operations listed above. Phase Two involves applying Gridlweb technologies to the User-based services and development of portals for access by users. Phase Three will allow NASA and end users to evaluate the services and determine the future of the technology as applied to space flight operational services. Although, Phase One, which includes the development of the quasi-operational User-based services of the prototype, development will be completed by March 2004, the application of Grid technologies to these services will have just begun. We will provide status of the Grid technologies to the individual User-based services. This effort will result in an extensible environment that incorporates existing and new spaceflight services into a standards-based framework providing current and future NASA programs with cost savings and new and evolvable methods to conduct science. This project will demonstrate how the use of new programming paradigms such as web and grid services can provide three significant benefits to the cost-effective delivery of spaceflight services. They will enable applications to operate more efficiently by being able to utilize pooled resources. They will also permit the reuse of common services to rapidly construct new and more powerful applications. Finally they will permit easy and secure access to services via a combination of grid and portal technology by a distributed user community consisting of NASA operations centers, scientists, the educational community and even the general population as outreach. The approach will be to deploy existing mission support applications such as the Telescience Resource Kit (TReK) and new applications under development, such as the Grid Video Distribution System (GViDS), together with existing grid applications and services such as high-performance computing and visualization services provided by NASA s Information Power Grid (IPG) in the MSFC s Payload Operations Integration Center (POIC) HOSC Annex. Once the initial applications have been moved to the grid, a process will begin to apply the new programming paradigms to integrate them where possible. For example, with GViDS, instead of viewing the Distribution service as an application that must run on a single node, the new approach is to build it such that it can be dispatched across a pool of resources in response to dynamic loads. To make this a reality, reusable services will be critical, such as a brokering service to locate appropriate resource within the pool. This brokering service can then be used by other applications such as the TReK. To expand further, if the GViDS application is constructed using a services-based mel, then other applications such as the Video Auditorium can then use GViDS as a service to easily incorporate these video streams into a collaborative conference. Finally, as these applications are re-factored into this new services-based paradigm, the construction of portals to integrate them will be a simple process. As a result, portals can be tailored to meet the requirements of specific user communities.

Bradford, Robert N.↗

Aviation security screening optimizer for risk and throughput (ASSORT)

The increasing number of air travelers each year presents a challenge as many airports are near their capacity in terms of resources and space for passenger screening. Fortunately, advancements in technologies like next-generation millimeter wave scanning offer solutions to ease this strain. The focus remains on managing risk while enhancing the passenger experience for the traveling public. The risk model presented in this paper known as the Aviation Security Screening Optimizer for Risk and Throughput (ASSORT) is designed to assess risk-based approaches for passenger screening and checkpoint operations. Additionally, ASSORT is exploring various traveler categories — general, trusted, and trusted-plus — along with different checkpoint screening Concept of Operations tailored to each traveler type. For instance, travelers with a higher trust level may experience fewer screening technologies, resulting in quicker processing times at the checkpoint. The output of ASSORT provides a risk score for predefined threat scenarios, as well as the overall risk to the checkpoint, aircraft, and airport by traveler type. In conclusion, benefits of using this tool include assessing the trade-offs between the overall risk associated with checkpoints and the throughput rate of passengers screened. We show for example the impact that different passenger volumes at the checkpoint can have on risk.

99 GENERAL AND MISCELLANEOUS↗

Radiochemical transport analysis of gamma spectroscopic data to support estimation of molten salt reactor off-gas inventories

This work introduces a novel application of radiochronometry to estimate nuclide inventories in molten salt reactor off-gas systems based on gamma spectroscopic data from the Molten Salt Reactor Experiment. By analyzing isotopic, isobaric, and isomeric activity ratios, key depletion model parameters related to species transport within the reactor system could be inferred. The findings demonstrate the potential of leveraging a limited subset of gamma spectroscopy measurements to accurately estimate nuclide inventories throughout the off-gas system. The approach can be useful in reactor design activities and support analyses relevant to operations, safety, security, and safeguards.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Engineering Controls Database

Cyber-Informed Engineering (CIE) addresses the reality that cyber attacks on engineered systems can have consequences far beyond data loss or disruption of digital networks. When control systems are compromised, safety, reliability, and performance of the physical process itself may be threatened. This database is meant to establish clear examples and guidance for defining and applying engineered controls in CIE. It explains what engineered controls are, how they differ from information security measures, and how they are integrated into system design. The goal is to ensure that resilience is engineered into systems from the outset. Unlike cybersecurity protections that defend the digital layer, engineered controls act directly at the physical and algorithmic levels to guarantee that unacceptable consequences are prevented or limited. CIE keeps the consequences of a cyber attack from impacting the safety, reliability, and performance of engineered systems.

Source record↗

Aviation Security Screening Optimizer for Risk and ThroughputASSORT

The Aviation Security Screening Optimizer for Risk and Throughput (ASSORT) is designed to assess risk-based approaches for passenger screening and checkpoint operations. Additionally, ASSORT is exploring various traveler categories — general, trusted, and trusted-plus — along with different checkpoint screening Concept of Operations tailored to each traveler type

Brigantic, Robert [Pacific Northwest National Labo↗

Cyber-Informed Engineering (CIE) – Engineered Controls Database and Use

Cyber-Informed Engineering (CIE) addresses the reality that cyber-attacks on engineered systems can have consequences far beyond data loss or disruption of digital networks. When control systems are compromised, safety, reliability, and performance of the physical process itself may be threatened. This database is meant to establish clear examples and guidance for defining and applying engineered controls in CIE. It explains what engineered controls are, how they differ from information security measures, and how they are integrated into system design. The goal is to ensure that resilience is engineered into systems from the outset. Unlike cybersecurity protections that defend the digital layer, engineered controls act directly at the physical and algorithmic levels to guarantee that unacceptable consequences are prevented or limited. CIE keeps the consequences of a cyber attack from impacting the safety, reliability, and performance of engineered systems.

42 - ENGINEERING↗

Symbology Development for General Aviation Synthetic Vision Primary Flight Displays for the Approach and Missed-Approach Modes of Flight

Spatial disorientation induced by inadvertent flight into instrument meteorological conditions (IMC) continues to be a leading cause of fatal accidents in general aviation. The Synthetic Vision Systems General Aviation (SVS-GA) research element, an integral part of NASA s Aviation Safety and Security Program (AvSSP), is investigating a revolutionary display technology designed to mitigate low visibility events such as controlled flight into terrain (CFIT) and low-visibility loss of control (LVLoC). The integrated SVS Primary Flight Display (SVS-PFD) utilizes computer generated 3-dimensional imagery of the surrounding terrain augmented with flight path guidance symbology. This unique combination will provide GA pilots with an accurate representation of their environment and projection of their flight path, regardless of time of day or out-the-window (OTW) visibility. The initial Symbology Development for Head-Down Displays (SD-HDD) simulation experiment examined 16 display configurations on a centrally located high-resolution PFD installed in NASA s General Aviation Work Station (GAWS) flight simulator. The results of the experiment indicate that situation awareness (SA) can be enhanced without having a negative impact on flight technical error (FTE), by providing a general aviation pilot with an integrated SVS display to use when OTW visibility is obscured.

Bartolone, Anthony P.↗

An Innovative Aperture Cover Mechanism Used on SDO/EVE and MMS/SDP

This paper describes an aperture cover mechanism that was successfully flown in four locations on SDO/EVE, and is awaiting launch in sixteen locations on MMS. This design uses a paraffin actuator and a latch that secures the cover closed and removes the actuator from the load path. This latch allows the assembly to operate both as a light weight contamination cover (SDO/EVE), and also as a high-strength sensor restraint mechanism (MMS/SDP). The paper provides design/analysis/test information about the mechanism.

Steg, Stephen↗

Engineering Against Digital Risk in CIP Applications: Cyber-Informed Engineering Use Cases

Cyber-Informed Engineering (CIE) addresses the reality that cyber attacks on engineered systems can have consequences far beyond data loss or disruption of digital networks. When control systems are compromised, safety, reliability, and performance of the physical process itself may be threatened. This presentation discusses engineered controls of 7 categories and the CIE database of controls that provides clear examples and guidance for defining and applying engineered controls in CIE. It explains what engineered controls are, how they differ from information security measures, and how they are integrated into system design.

99 - GENERAL AND MISCELLANEOUS↗

Integrating science for water security governance

Hydrological extremes are intensifying globally, increasing the complexity of decisions required to ensure water security. Advances in hydrological science, modeling, and data systems have expanded the technical frontier of water research, yet uptake of scientific insights in policy and management decisions remains limited. This persistent science–policy gap is not primarily a failure of knowledge generation or robustness, but an institutional challenge shaped by how scientific and governance systems are organized, coordinated, and connected to support the effective use of scientific knowledge. These challenges are particularly pronounced in multi-level and transboundary water governance, where decisions span jurisdictions and require coordination across institutional and political boundaries. We synthesize research at the science–policy interface and evidence from water security initiatives to show how institutional arrangements, scientific tool development, and research practices enable or constrain the sustained use of scientific knowledge in water-security governance processes. Building on these insights, we develop ‘shared decision infrastructure’ as a framing to describe how scientific knowledge is embedded within the institutional, relational, and procedural arrangements that connect science to decision-making processes over time. We translate this framing into a practical intervention roadmap centered on institutional design, tool translation, sustained co-production, and outcome-oriented evaluation to support the integration of science into ongoing governance processes. By positioning science as shared decision infrastructure, the roadmap clarifies how researchers can design scientific efforts that support more coordinated, accountable, and adaptive water security decisions amid deepening uncertainty.

M whitney, Kristen [NASA Goddard Space Flight Cent↗