Search NASA⌕ Search

SEARCH · Search NASA

Results for “Secure by Design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 289 records · Page 16

Fixed Or Controlled-Movement Foot Restraint

Foot restraint gives user three options: holds user's feet in fixed position, allows them to slide sideways, or allows them to pivot independently about axis through ball of foot, as user chooses. Selects degree of restraint to suit task at hand. Movements to enter and leave foot restraint simple and direct. Simply forces each cleat lightly into space between rails until spring force of movable rail secures it. Body movements for sliding and rotation equally straightforward. Designed for use in absence of gravitation, restraint useful on Earth, underwater or in some hazardous locations where movements restricted.

Reilly, Gloria B.↗

Addressing the Tension Between Strong Perimeter Control an Usability

This paper describes a strong perimeter control system for a general purpose processing system, with the perimeter control system taking significant steps to address usability issues, thus mitigating the tension between strong perimeter protection and usability. A secure front end enforces two-factor authentication for all interactive access to an enclave that contains a large supercomputer and various associated systems, with each requiring their own authentication. Usability is addressed through a design in which the user has to perform two-factor authentication at the secure front end in order to gain access to the enclave, while an agent transparently performs public key authentication as needed to authenticate to specific systems within the enclave. The paper then describes a proxy system that allows users to transfer files into the enclave under script control, when the user is not present to perform two-factor authentication. This uses a pre-authorization approach based on public key technology, which is still strongly tied to both two-factor authentication and strict control over where files can be transferred on the target system. Finally the paper describes an approach to support network applications and systems such as grids or parallel file transfer protocols that require the use of many ports through the perimeter. The paper describes a least privilege approach that dynamically opens ports on a host-specific, if-authorized, as-needed, just-in-time basis.

Hinke, Thomas H.↗

Application of a Novel Long-Reach Manipulator Concept to Asteroid Redirect Missions

A high priority mission currently being formulated by NASA is to capture all or part of an asteroid and return it to cis-lunar space for examination by an astronaut crew. Two major mission architectures are currently being considered: in the first (Mission Concept A), a spacecraft would rendezvous and capture an entire free flying asteroid (up to 14 meters in diameter), and in the second (Mission Concept B), a spacecraft would rendezvous with a large asteroid (which could include one of the Martian moons) and retrieve a boulder (up to 4 meters in diameter). A critical element of the mission is the system that will capture the asteroid or boulder material, enclose it and secure it for the return flight. This paper describes the design concepts, concept of operations, structural sizing and masses of capture systems that are based on a new and novel Tendon- Actuated Lightweight In-Space MANipulator (TALISMAN) general-purpose robotic system. Features of the TALISMAN system are described and the status of its technology development is summarized. TALISMAN-based asteroid material retrieval system concepts and concepts-of-operations are defined for each asteroid mission architecture. The TALISMAN-based capture systems are shown to dramatically increase operational versatility while reducing mission risk. Total masses of TALISMAN-based systems are presented, reinforcing the mission viability of using a manipulator-based approach for the asteroid redirect mission.

Dorsey, John T.↗

NASA Earth eXchange (NEX) App Store

NASA Earth Exchange (NEX), and her public cloud version OpenNEX, have become platforms supporting scientific collaboration, knowledge sharing and research for the entire Earth science community. To date, a number of custom tools and capabilities have been integrated into the platforms. However, such integration has to undergo a case-by-case manual process thus lacks scalability. This timely project builds an App Store onto OpenNEX as a building block. Climate data analytics tools/programs can be easily uploaded, shared, organized, searched, and recommended like photos and videos on the YouTube. The foundation of our App Store is a provenance server, which not only records metadata but also execution history of climate data analytics apps including the input data and parameters, output data and products, who runs the app for which purpose, and how apps may be chained into workflows. Researchers can thus understand, reproduce, and repurpose existing apps and workflows. Machine learning approaches are applied to mine provenance to provide recommend-as-you-go services for Earth scientists, such as to recommend suitable apps and workflow snippets. A browser-based workflow tool is also provided for researchers to explore the provenance server and design value-added workflows. Scalability, sustainability, extensibility, usability, adaptability, security and privacy are considered in the App Store.

eXchange↗

An Introduction to the Federated Architecture for Secure and Transactive Distributed Energy Management Solutions (FAST-DERMS): Preprint

Deployment and capability of distributed energy resources (DER) in power systems is growing rapidly. These resources present an opportunity for low-cost provision of energy and grid services. The Federal Energy Regulatory Commission recently provided rulings to enable market participation of these distribution-connected resources, but the prevailing strategies for their management may not scale well to meet future needs. This paper introduces the Federated Architecture for Secure and Transactive Distributed Energy Management Solutions (FASTDERMS) which was designed to address this need. In it we describe the architectural features of the approach, and a reference controls implementation employing a hierarchical coordination that includes stochastic optimization, model predictive control, and a simple real-time management scheme. Sample results from simulation show firm transmission-level service provision measured at the distribution substation.

DERMS↗

The design and implementation of EPL: An event pattern language for active databases

The growing demand for intelligent information systems requires closer coupling of rule-based reasoning engines, such as CLIPS, with advanced data base management systems (DBMS). For instance, several commercial DBMS now support the notion of triggers that monitor events and transactions occurring in the database and fire induced actions, which perform a variety of critical functions, including safeguarding the integrity of data, monitoring access, and recording volatile information needed by administrators, analysts, and expert systems to perform assorted tasks; examples of these tasks include security enforcement, market studies, knowledge discovery, and link analysis. At UCLA, we designed and implemented the event pattern language (EPL) which is capable of detecting and acting upon complex patterns of events which are temporally related to each other. For instance, a plant manager should be notified when a certain pattern of overheating repeats itself over time in a chemical process; likewise, proper notification is required when a suspicious sequence of bank transactions is executed within a certain time limit. The EPL prototype is built in CLIPS to operate on top of Sybase, a commercial relational DBMS, where actions can be triggered by events such as simple database updates, insertions, and deletions. The rule-based syntax of EPL allows the sequences of goals in rules to be interpreted as sequences of temporal events; each goal can correspond to either (1) a simple event, or (2) a (possibly negated) event/condition predicate, or (3) a complex event defined as the disjunction and repetition of other events. Various extensions have been added to CLIPS in order to tailor the interface with Sybase and its open client/server architecture.

Giuffrida, G.↗

Security constrained optimal power shutoff for wildfire risk mitigation

Abstract Electric grid faults are increasingly the source of ignition for major wildfires. To reduce the likelihood of such ignitions in high risk situations, utilities use preemptive de‐energization of power lines, commonly referred to as Public Safety Power Shutoffs (PSPS). Besides raising challenging trade‐offs between power outages and wildfire safety, PSPS removes redundancy from the network at a time when component faults are likely to happen. This may leave the network particularly vulnerable to unexpected line faults that may occur while the PSPS is in place. Previous works have not explicitly considered the impacts of these outages. To address this gap, the Security Constrained Optimal Power Shutoff problem is proposed which uses post‐contingency security constraints to model the impact of unexpected line faults when planning a PSPS. This model enables, for the first time, the exploration of a wide range of trade‐offs between both wildfire risk and pre‐ and post‐contingency load shedding when designing PSPS plans, providing useful insights for utilities and policy makers considering different approaches to PSPS. The efficacy of the model is demonstrated using the EPRI 39‐bus system as a case study. The results highlight the potential risks of not considering security constraints when planning PSPS and show that incorporating security constraints into the PSPS design process improves the resilience of current PSPS plans.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Quality and security - They work together

This paper describes the importance of considering computer security as part of software quality assurance practice. The intended audience is primarily those professionals involved in the design, development, and quality assurance of software. Many issues are raised which point to the need ultimately for integration of quality assurance and computer security disciplines. To address some of the issues raised, the NASA Automated Information Security program is presented as a model which may be used for improving interactions between the quality assurance and computer security community of professionals.

Carr, Richard↗

Maximizing Launch Vehicle and Payload Design Via Early Communications

The United States? current fleet of launch vehicles is largely derived from decades-old designs originally made for payloads that no longer exist. They were built primarily for national security or human exploration missions. Today that fleet can be divided roughly into small-, medium-, and large-payload classes based on mass and volume capability. But no vehicle in the U.S. fleet is designed to accommodate modern payloads. It is usually the payloads that must accommodate the capabilities of the launch vehicles. This is perhaps most true of science payloads. It was this paradigm that the organizers of two weekend workshops in 2008 at NASA's Ames Research Center sought to alter. The workshops brought together designers of NASA's Ares V cargo launch vehicle (CLV) with scientists and payload designers in the astronomy and planetary sciences communities. Ares V was still in a pre-concept development phase as part of NASA?s Constellation Program for exploration beyond low Earth orbit (LEO). The space science community was early in a Decadal Survey that would determine future priorities for research areas, observations, and notional missions to make those observations. The primary purpose of the meetings in April and August of 2008, including the novel format, was to bring vehicle designers together with space scientists to discuss the feasibility of using a heavy lift capability to launch large observatories and explore the Solar System. A key question put to the science community was whether this heavy lift capability enabled or enhanced breakthrough science. The meetings also raised the question of whether some trade-off between mass/volume and technical complexity existed that could reduce technical and programmatic risk. By engaging the scientific community early in the vehicle design process, vehicle engineers sought to better understand potential limitations and requirements that could be added to the Ares V from the mission planning community. From the vehicle standpoint, while the human exploration mission could not be compromised to accommodate other payloads, the design might otherwise be tailored to not exclude other payload requirements. This paper summarizes the findings of the workshops and discusses the benefits of bringing together the vehicle design and science communities early in their concept phases

Morris, Bruce↗

Flange design for large-scale modular assembly jigs

Technique incorporates weld-free method for securing flanges to projecting ends of unmachined box-beam framework so flanged structure may be reused without modification. One such framework may be readily assembled to another by simply matching flanges together and passing connecting members between preformed holes in structures.

Gilman, M. M.↗

Towards Behavioral Reflexion Models

Software architecture has become essential in the struggle to manage today s increasingly large and complex systems. Software architecture views are created to capture important system characteristics on an abstract and, thus, comprehensible level. As the system is implemented and later maintained, it often deviates from the original design specification. Such deviations can have implication for the quality of the system, such as reliability, security, and maintainability. Software architecture compliance checking approaches, such as the reflexion model technique, have been proposed to address this issue by comparing the implementation to a model of the systems architecture design. However, architecture compliance checking approaches focus solely on structural characteristics and ignore behavioral conformance. This is especially an issue in Systems-of- Systems. Systems-of-Systems (SoS) are decompositions of large systems, into smaller systems for the sake of flexibility. Deviations of the implementation to its behavioral design often reduce the reliability of the entire SoS. An approach is needed that supports the reasoning about behavioral conformance on architecture level. In order to address this issue, we have developed an approach for comparing the implementation of a SoS to an architecture model of its behavioral design. The approach follows the idea of reflexion models and adopts it to support the compliance checking of behaviors. In this paper, we focus on sequencing properties as they play an important role in many SoS. Sequencing deviations potentially have a severe impact on the SoS correctness and qualities. The desired behavioral specification is defined in UML sequence diagram notation and behaviors are extracted from the SoS implementation. The behaviors are then mapped to the model of the desired behavior and the two are compared. Finally, a reflexion model is constructed that shows the deviations between behavioral design and implementation. This paper discusses the approach and shows how it can be applied to investigate reliability issues in SoS.

Ackermann, Christopher↗

Dependable classical-quantum computing systems engineering

Increasing evidence suggests quantum computing (QC) complements traditional High-Performance Computing (HPC) by leveraging its unique capabilities, leading to the emergence of a new, hybrid paradigm, QHPC. However, this integration introduces new challenges, with dependability–defined by reproducibility, resiliency, and security and privacy–emerging as a central concern for building trustworthy systems that provide an advantage to the users. This paper proposes a framework for dependable QHPC system design, organized around these three pillars. We identify integration challenges, anticipate roadblocks, and highlight productive synergies across QC, HPC, cloud platforms, and network security. Drawing from both classical computing principles and quantum-specific insights, we present a roadmap for co-design that supports robust hybrid architectures. Our approach offers concrete metrics for assessing dependability, provides design guidance for engineers working at the QC-HPC interface, and surfaces new engineering questions around complexity, scale, and fault tolerance. Ultimately, designing for dependability is key to realizing practical, scalable QHPC systems and accelerating the broader quantum ecosystem capable of translating quantum promises into actual application delivery.

HPC↗

The Design and Evaluation of Zero Trust Architecture for Electric Vehicle Charging Infrastructure: EVs @ Scale Series on EV Charging Station Cybersecurity

Implementing a zero trust architecture can significantly bolster the security of electric vehicle (EV) charging infrastructure. EV charging infrastructure includes numerous networked interfaces, each of which can present potential vulnerabilities. When these vulnerabilities are exploited, they can compromise the entire system, leading to severe operational and security risks. Zero trust is a security model that operates on the principle of "never trust, always verify," which helps manage the attack surface and limit the scope of any potential compromises. Fundamentally, this model ensures that no entity, whether inside or outside the network, is trusted by default. The design principles of zero trust include continuous verification, strict deny-by-default access controls, and micro-segmentation. Continuous verification ensures that every request is thoroughly checked, regardless of its origin. Strict access controls enforce the principle of least privilege, allowing users and devices only the minimum necessary access to perform their functions. Micro-segmentation involves dividing the network into smaller, isolated segments to prevent lateral movement in case of a breach. In the context of EV charging infrastructure, zero trust can be implemented through various strategies. For example, multi-factor authentication (MFA) can be required for engineers to access the management interfaces and control systems of charging stations. Real-time monitoring and analysis of network traffic can help detect and respond to anomalies. Systems that do not need to communicate with each other can be micro-segmented to enhance security. All communications should adhere to predefined policies to be permitted. Additionally, encrypting communications can protect sensitive information exchanged between chargers and management systems. This paper presents a zero trust architecture specifically designed for EV charging infrastructure. Implementing zero trust not only mitigates risks but also builds a resilient infrastructure capable of withstanding and quickly recovering from cyber threats. The architecture addresses six defined security objectives. A comprehensive test plan is developed to assess the architecture against these objectives, and the results of the evaluation are reported. This approach is essential for maintaining the reliability and integrity of EV charging services in an increasingly interconnected and vulnerable digital landscape. This is the first in a planned series of papers exploring the implementation of zero trust in EV charging infrastructure. Each paper will delve into different aspects and applications of zero trust, highlighting how various work processes and requirements can lead to distinct architectural designs. These architectures will be tailored to address specific security challenges and operational needs within the EV charging ecosystem, ensuring a robust and adaptable security framework.

33 ADVANCED PROPULSION SYSTEMS↗

Implementation and Demonstration of the Digital Twin Certification System Remote Operations Framework

Microreactors are one promising advanced-reactor concept being pursued by the nuclear industry. They are distinguished by a relatively low power output of 20 MWth or less. These microreactors are intended for deployment in applications where conventional small-capacity power solutions, such as diesel generators, are either economically unfeasible or logistically challenging. Such applications include providing electric power and/or heat for remote communities, mining sites, defense installations, and humanitarian and disaster-relief missions. An important feature for the successful deployment of microreactors is their capability to be operated remotely. This capability can significantly reduce staffing costs by eliminating the need for licensed operators to be physically present at each reactor site. Instead, operators can be centralized in a single remote operations center placed in an economically advantageous location, thereby optimizing resources by consolidating expertise and enhancing operational efficiency. However, the implementation of a remote operation system for nuclear reactors raises new concerns regarding the security, reliability, and resilience of such a system. One way in which remote operations can be supported in a manner that maintains system security, reliability, and resilience is through the use of digital twins in a novel framework designed to verify and validate sensor data and commands communicated between the remote operations center and reactor. This framework, known as the Digital Twin Certification System (DTCS), has previously been proposed as an operations architecture that can bring security and resiliency levels of remote nuclear-reactor operations to a level acceptable for commercial deployment. This paper moves the proposed DTCS architecture from concept to reality by presenting the implementation and testing of the system. The rationale and implementation of the DTCS using tools such as DeepLynx and Apache Airflow, is covered in-depth. This is followed by a demonstration of the DTCS by applying the implemented system architecture to the Single Primary Heat Extraction and Removal Emulator, a small-scale non-nuclear test bed that emulates thermal behavior of a microreactor. The demonstration includes both normal and abnormal operating scenarios to highlight how the DTCS can increase the security, reliability, and resilience of a remote operations system.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Implementation and Demonstration of the Digital Twin Certification System Remote Operations Framework

Microreactors are one promising advanced-reactor concept being pursued by the nuclear industry. They are distinguished by a relatively low power output of 20 MWth or less. These microreactors are intended for deployment in applications where conventional small-capacity power solutions, such as diesel generators, are either economically unfeasible or logistically challenging. Such applications include providing electric power and/or heat for remote communities, mining sites, defense installations, and humanitarian and disaster-relief missions. An important feature for the successful deployment of microreactors is their capability to be operated remotely. This capability can significantly reduce staffing costs by eliminating the need for licensed operators to be physically present at each reactor site. Instead, operators can be centralized in a single remote operations center placed in an economically advantageous location, thereby optimizing resources by consolidating expertise and enhancing operational efficiency. However, the implementation of a remote operation system for nuclear reactors raises new concerns regarding the security, reliability, and resilience of such a system. One way in which remote operations can be supported in a manner that maintains system security, reliability, and resilience is through the use of digital twins in a novel framework designed to verify and validate sensor data and commands communicated between the remote operations center and reactor. This framework, known as the Digital Twin Certification System (DTCS), has previously been proposed as an operations architecture that can bring security and resiliency levels of remote nuclear-reactor operations to a level acceptable for commercial deployment. This paper moves the proposed DTCS architecture from concept to reality by presenting the implementation and testing of the system. The rationale and implementation of the DTCS using tools such as DeepLynx and Apache Airflow, is covered in-depth. This is followed by a demonstration of the DTCS by applying the implemented system architecture to the Single Primary Heat Extraction and Removal Emulator, a small-scale non-nuclear test bed that emulates thermal behavior of a microreactor. The demonstration includes both normal and abnormal operating scenarios to highlight how the DTCS can increase the security, reliability, and resilience of a remote operations system.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Multi-Organization Multi-Discipline Effort Developing a Mitigation Concept for Planetary Defense

There have been significant recent efforts in addressing mitigation approaches to neutralize Potentially Hazardous Asteroids (PHA). One such research effort was performed in 2015 by an integrated, inter-disciplinary team of asteroid scientists, energy deposition modeling scientists, payload engineers, orbital dynamist engineers, spacecraft discipline engineers, and systems architecture engineer from NASAs Goddard Space Flight Center (GSFC) and the Department of Energy (DoE) National Nuclear Security Administration (NNSA) laboratories (Los Alamos National Laboratory (LANL), Lawrence Livermore National Laboratories (LLNL) and Sandia National Laboratories). The study team collaborated with GSFCs Integrated Design Centers Mission Design Lab (MDL) which engaged a team of GSFC flight hardware discipline engineers to work with GSFC, LANL, and LLNL NEA-related subject matter experts during a one-week intensive concept formulation study in an integrated concurrent engineering environment. This team has analyzed the first of several distinct study cases for a multi-year NASA research grant. This Case 1 study references the Near-Earth Asteroid (NEA) named Bennu as the notional target due to the availability of a very detailed Design Reference Asteroid (DRA) model for its orbit and physical characteristics (courtesy of the Spectral Interpretation, Resource Identification, Security-Regolith Explorer (OSIRIS-REx) mission team). The research involved the formulation and optimization of spacecraft trajectories to intercept Bennu, overall mission and architecture concepts, and high-fidelity modeling of both kinetic impact (spacecraft collision to change a NEAs momentum and orbit) and nuclear detonation effects on Bennu, for purposes of deflecting Bennu.

Planetary Defense↗

A Formal Model of Partitioning for Integrated Modular Avionics

The aviation industry is gradually moving toward the use of integrated modular avionics (IMA) for civilian transport aircraft. An important concern for IMA is ensuring that applications are safely partitioned so they cannot interfere with one another. We have investigated the problem of ensuring safe partitioning and logical non-interference among separate applications running on a shared Avionics Computer Resource (ACR). This research was performed in the context of ongoing standardization efforts, in particular, the work of RTCA committee SC-182, and the recently completed ARINC 653 application executive (APEX) interface standard. We have developed a formal model of partitioning suitable for evaluating the design of an ACR. The model draws from the mathematical modeling techniques developed by the computer security community. This report presents a formulation of partitioning requirements expressed first using conventional mathematical notation, then formalized using the language of SRI'S Prototype Verification System (PVS). The approach is demonstrated on three candidate designs, each an abstraction of features found in real systems.

DiVito, Ben L.↗

Lightweight helmet-mounted eye movement measurement system

The helmet-mounted eye movement measuring system, weighs 1,530 grams; the weight of the present aviators' helmet in standard form with the visor is 1,545 grams. The optical head is standard NAC Eye-Mark. This optical head was mounted on a magnesium yoke which in turn was attached to a slide cam mounted on the flight helmet. The slide cam allows one to adjust the eye-to-optics system distance quite easily and to secure it so that the system will remain in calibration. The design of the yoke and slide cam is such that the subject can, in an emergency, move the optical head forward and upward to the stowed and locked position atop the helmet. This feature was necessary for flight safety. The television camera that is used in the system is a solid state General Electric TN-2000 with a charged induced device imager used as the vidicon.

Barnes, J. A.↗