Search NASA⌕ Search

SEARCH · Search NASA

Results for “authentication”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

288 records · Page 16

New Cryogenic Method for Combining Lunar Regolith Simulant and Frozen Volatiles to Generate Icy Lunar Simulated Regolith

There is a requirement within the lunar science and exploration communities to develop lunar simulants containing volatiles that are solids at the cryogenic temperatures found in the permanently shadowed regions (PSRs), such as those found near the Lunar South Pole. Icy regolith simulants would be used for curation training, as well as for various research activities. One of the most critical aspects of developing a regolith simulant that is more physically and chemically like icy lunar regolith is minimizing any form of modification driven by elevated temperatures. Here we document our ongoing efforts to combine materials at ultralow temperatures, designed to minimize any chemical reactions or other physical changes during the production of the icy regolith. Our goal is to document how one can create an essentially “unreacted” icy regolith that can serve as an effective “time zero” start point from which advanced curation research will proceed. This is done using commercial off-the-shelf equipment as much as possible, along with creating a custom spray plate that can be adapted to a wide variety of methods, all for the planetary simulant community. This method creates crystals of various volatiles such as water, methanol, along with CO 2 ice and these components are combined with lunar regolith that is at -196°C temperature to avoid chemical reactions, and/or phase changes thus creating a more chemically relevant icy lunar regolith. The rules of chemistry stay the same regardless of location whether it’s in the lab, or directly on the lunar surface, and therefore we aim for creating a more authentic icy lunar simulant in the laboratory by operating at ultralow temperatures. It is also envisioned that this method will lead to advanced materials testing in the future. In addition, this method is directly applicable to prior missions such as LCROSS.

Cryogenic Lunar Simulant and Icy Volatile Producti↗

Scenario-Based Task Design for Airline Pilot Anticipatory Behaviors: Asynchronous Assessment of Complex Cognitive Skills

Airline pilots must anticipate potential threats to passenger safety and efficient flight. Such anticipation needs to occur at both the system and individual levels, yet no formal training for these anticipatory behaviors currently exists. The emerging field of resilience engineering provides a framework to explore this problem. Given the complex nature of this problem, the assessment portion of the project constituted a challenge. Simulator time is expensive as simulators are costly to run, and they are extremely limited in number. Also, by the nature of their work, pilots as a group are hard to connect with in person; thus, asynchronous methods were adopted. Further, to ensure that authentic pilot behaviors were observed, task-based scenarios were used rather than focus group or interview protocols. This session explores the design of asynchronous learning and a measure for assessing pilot anticipatory behaviors outside of a simulator to help design learning opportunities for pilots. The scenario-based and active assessment items will be discussed in detail, and demonstrations of these items will be shared. These items constitute the bulk of the challenge for this work. At the time of this writing, data is being collected to assess the effectiveness of the interactive training module and validate the measures. This data will be analyzed and presented as part of the session. This will include any linkages between the scenario-based and traditional assessment items.

task design↗

Laser Based Ultrasound for Verification of Circuit Card Assemblies

This IR is a follow-up conference Paper to the IR approved abstract; PNNL-SA-194096. --- Verification that equipment is authentic and not changed; even at the circuit card assembly (CCA) level will likely be an important component of future arms control treaties. This effort was an initial evaluation of the potential for laser-based ultrasound (LBU) as an inspection tool for Unique Identification (UID) of Circuit Card Assembly (CCA) boards and CCA components. The LBU system used a laser pulse for ultrasound generation and an Optical Microphone for ultrasound detection to image subsurface structures without physical contact and in a dry state. This paper described the selected CCA surrogate, CCA components that were examined, the LBU system, LBU images of the CCA components, and the initial development of UID algorithms. Receiver operating characteristics (ROC) curves indicated good performance for two algorithms as a potential means for UID of CCA boards and CCA components.

Laser Ultrasound, Equipment Verification, Arms Con↗

Verifying Cyber Implementation Best Practices With Malcolm

Network traffic analysis can reveal a lot about what's right or wrong with a network's cybersecurity footing. Using Malcolm, a powerful open-source network traffic analysis tool suite for network security monitoring, cyber analysts and asset owners can validate cybersecurity best practices and uncover red flags in network configuration, including: proper network segmentation east-west (cross-segment) and north-south traffic unsecure or outdated network protocols authentication using clear text credentials rogue devices and services unexpected protocols (e.g., IPv6, DNS, DHCP, update checks, etc.) suspicious file transfers

99 GENERAL AND MISCELLANEOUS↗

A Managed Tokens Service for Securely Keeping and Distributing Grid Tokens

Fermilab is transitioning authentication and authorization for grid operations to using bearer tokens based on the WLCG Common JWT (JSON Web Token) Profile. One of the functionalities that Fermilab experimenters rely on is the ability to automate batch job submission, which in turn depends on the ability to securely refresh and distribute the necessary credentials to experiment job submit points. Thus, with the transition to using tokens for grid operations, we needed to create a service that would obtain, refresh, and distribute tokens for experimenters' use. This service would avoid the need for experimenters to be experts in obtaining their own tokens and would better protect the most sensitive long-lived credentials. Further, the service needed to be widely scalable, as Fermilab hosts many experiments, each of which would need their own credentials. To address these issues, we created and deployed a Managed Tokens Service. The service is written in Go, taking advantage of that language's native concurrency primitives to easily be able to scale operations as we onboard experiments. The service uses as its first credentials a set of kerberos keytabs, stored on the same secure machine that the Managed Tokens service runs on. These kerberos credentials allow the service to use htgettoken via condor_vault_storer to store vault tokens in the HTCondor credential managers (credds) that run on the batch system scheduler machines (HTCondor schedds); as well as downloading a local, shorter-lived copy of the vault token. The kerberos credentials are then also used to distribute copies of the locally-stored vault tokens to experiment submit points.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

Shape Optimization of Header Pipes in Power Plants for Enhanced Efficiency and Environmental Sustainability

In a power plant, the header pipe plays a pivotal role in optimizing the performance of diverse systems by serving as a central conduit for the collection and distribution of steam within the plant. This paper investigates the significance of header pipes within power plant setups, highlighting their critical influence on reliability, efficiency, and the performance of the power plant as a whole. The concept of shape optimization emerges as a crucial factor in power plant design and operation, with the potential to maximize performance while minimizing the use of materials. Shape optimization not only enhances efficiency but also contributes to reducing the environmental footprint of power plant installations. In this paper, we initially developed a methodology designed for optimizing header shapes with the primary goal of reducing the usage of costly new alloy materials and lowering the overall maintenance operation expenses. Secondly, we conducted a case study based on an authentic header sourced from an operational power plant.

20 FOSSIL-FUELED POWER PLANTS↗

Improving Cyber Situational Understanding

Effective cybersecurity operations require the ability to analyze large amounts of information to assess security risks and formulate defensive strategies against adversaries. This has become more complex in recent years as the sprawl and interconnectivity of devices grows through implementation of virtualization, cloud computing, and Internet of Things (IoT). The amount of data and analysis required for effective cybersecurity command and control decisions far exceeds humans’ capacity to perform manually. We characterize the analysis problem as cyber situational understanding. The research presented to improve cyber situational understanding focuses on vulnerability analysis and threat intelligence. Regarding vulnerabilities, entities must analyze and plan work for between thousands and tens of thousands of software vulnerabilities annually. Entities heavily use network firewalls to limit vulnerability exposure. As a result, some of these vulnerabilities permit exposure to adversarial exploitation, whereas others are inaccessible and therefore present negligible risk of exploitation. Distinguishing between high and low risk software vulnerabilities requires a deep understanding of the vulnerability, network firewall protection, and characteristics of the targeted device. This problem is solved by extracting network service features from vulnerability data features using both machine-learning and natural language processing. Then, the network firewall topology is parsed to determine which vulnerabilities are reachable by adversaries. Ultimately, a state-based safety analysis ascertains which vulnerabilities are unsafe. A related vulnerability analysis problem occurs in cybersecurity operations when associating an entity’s hardware and software assets to public vulnerability databases. Assets often reveal hardware and software through installation artifacts and network service identification, and entities store these artifacts in inventory databases. However, software and hardware vendors apply a standard Common Platform Enumeration (CPE) naming convention when publicly reporting vulnerabilities. Associating these two datasets often requires many hours to days of manual inspection. The proposed solution automates the mapping approach of human analysts using fuzzy matching techniques, natural language processing, and, ultimately, machine learning to present a small set of recommendations for mapping the two datasets. The result significantly reduces human analysis time and reduces the occurrence of false positives in vulnerability notifications. Finally, cyber threat intelligence (CTI) requires associating cyber observable artifacts, such as IP addresses, URIs, and file hashes, with cyber threat tactics, techniques, and procedures. Unfortunately, most CTI data is compartmentalized across multiple organizations and cannot be shared due to the legal and reputational risk with cyber threat being associated with the entity. The approach to solving this problem inovlves using a distributed ledger with anonymous token spending and authentication. This allows a consortium of semi-trusted entities to share the workload of curating CTI for a threat sharing community’s cooperative benefit.

Huff, Philip↗

Harnessing the Power of AI: Status and Expansion of Current Domestic Transport Security Through Flexible Embedded Hardware

As applications of Artificial Intelligence (AI) continue to expand, there are increasing opportunities to leverage applied AI methodologies with mobile transportation focused embedded systems. Current applications of AI in transportation focus on a variety of areas, including fuel efficiency, safety, security, and other broad fields of optimization or detection. To leverage these AI workflows and methodologies in the field, teams must utilize complex embedded systems capable of implementing these AI-enabled algorithms in real-time. In this paper, we will investigate how these algorithms can be integrated into existing technologies leveraging vehicle data - such as the Controller Area Network Transport Security Tracking and Reporting Unit (C-STAR). The C-STAR technology is an embedded platform with onboard computation capable of running next generation algorithms in vehicle systems AI, such as preventative maintenance, driver authentication, and transport security. As deployed in the field, the C-STAR has a limited AI functionality –this paper will directly discuss how a device like C-STAR can be utilized and the advantages of integrating these new technologies. We will open with relevant background information and transportation projects that leverage AI, focusing specifically on those around transport security such as vehicle identification, anomaly detection, and deterrence. We will then extend this into potential opportunities and scaling for AI methodologies using platforms like the C-STAR. Finally, we will speak directly to the challenges of deploying AI-powered workflows, such as computing power needs, bandwidth, hallucinations, and other regulatory considerations.

Cook, Adian [ORNL] (ORCID:0000000160825395)↗

DeepLynx Ecosystem 2025

Poor data integration and governance continue to plague complex engineering projects, resulting in missed cost, schedule, and performance targets. Departments operate in isolated systems with manual data exchange, creating fragmented information that compounds errors and leads to significant delays and cost overruns. The DeepLynx ecosystem addresses these challenges through an open-source, modular data management platform that transforms fragmented project data into an integrated digital thread. Built on a federated microservice architecture, the ecosystem comprises seven specialized tools centered around DeepLynx Nexus, a unified data catalog with hierarchical organization and graph-based navigation capabilities. The ecosystem includes: DeepLynx Stream for real-time timeseries data ingestion from industrial sources; DeepLynx Ingest for governed data uploads with formal review workflows; DeepLynx Lattice for ontology-based entity and relationship extraction; DeepLynx Run for workflow orchestration and secure AI/ML compute; DeepLynx Visualize for 3D digital twin visualization; and DeepLynx Insight for AI-assisted document analysis with traceable, grounded responses. Deployable in cloud, on-premise, or hybrid environments using containerized Docker applications and Helm charts, the DeepLynx ecosystem provides flexible infrastructure that adapts to organizational requirements. By consolidating project data into a unified data lake with role-based access controls and OAuth2 authentication, DeepLynx enables digital thread and digital twin capabilities that improve decision-making, reduce risk, and support complex engineering workflows throughout the project lifecycle.

42 - ENGINEERING↗

Portable and Cost-Effective Device for Reliable Detection of Counterfeit and Non-compliant Refrigerants in Diverse Applications

Counterfeit refrigerants pose significant challenges to safety, system reliability, and operational effectiveness due to their harmful contaminants or incompatible chemical compositions. Utilizing these noncompliant products can lead to reduced efficiency, equipment failures, and expensive repairs. Additionally, heightened demand for alternative refrigerants during the industry's transition has created supply gaps, enabling counterfeit products to proliferate. Accurate detection and analysis tools are therefore essential to verify refrigerant authenticity and ensure system integrity in diverse applications. This paper presents the development of a portable device designed for reliable identification and detailed analysis of refrigerant composition. By integrating precision gas sampling, controlled pressure regulation, and automated sensor technology, the device not only detects deviations from standard refrigerant properties but also provides a comprehensive composition breakdown. Pre-calibrated sensors measure the refrigerant gas to identify specific concentrations and contaminants, with an intuitive LED-based indicator system ensuring quick interpretation of results. The user-friendly interface enables operators to select refrigerant types for targeted testing, further enhancing accuracy and usability for field technicians. Comprehensive testing was conducted on mildly flammable A2L refrigerants, showcasing the device’s robustness and adaptability in analyzing composition and detecting discrepancies. The device demonstrated consistent accuracy across a range of refrigerant samples, affirming its reliability in diverse operational environments. Its design minimizes contamination risks during sampling and provides detailed composition results within 90 seconds, ensuring efficient and precise analysis. With a projected price point under $150, the proposed solution delivers affordability alongside its lightweight portability and straightforward operation. Unlike complex and costly alternatives, such as gas chromatography systems, this device provides an accessible option for technicians, customs personnel, and industry operators in need of quick and effective refrigerant verification. Compatible with both current formulations and emerging refrigerant technologies, the device addresses critical counterfeit detection needs across a range of applications. By delivering accurate composition analysis and counterfeit identification, this innovation enhances system performance, safety, and operational reliability in crucial industries.

Cheekatamarla, Praveen [ORNL] (ORCID:0000000248827↗

Latency Analysis of the Nexus Digital Twin Framework

Real-time digital catalogs are increasingly relied upon to track metadata and connect disparate data sources for cloud-based data integration efforts. One such tool, Deeplynx Nexus is supporting real-time digital twin efforts through event-driven data integration and time-series queries. Nexus’s usefulness for these applications depends critically on how quickly individual records can be uploaded and downloaded, since delays directly affect the responsiveness of any system built on top of it. However, the actual latency a user should expect from Nexus has not been systematically measured before, particularly for the small, frequent transactions typical of live sensor feeds. Here we show that single-record round-trip latency is 61.1 ms on a local Nexus instance and 391.7 ms on the hosted production infrastructure, a roughly 6.4x difference driven primarily by fixed per-request overhead rather than data volume. This overhead dominates at small scale: comparing single-record and ten-record trials suggests approximately 56 ms of each single-record request is fixed connection and authentication cost rather than data-transfer time, meaning batching even a handful of records is substantially more efficient than transmitting them individually. At large batch sizes, this pattern reverses for uploads, which converge to near parity between local and hosted environments by 25,000-50,000 records, while download latency remains persistently 5.7-6.4x slower on hosted infrastructure even at scale. These results suggest that Nexus deployments intended for real-time digital twin applications should prioritize record batching over single-record transactions, and that download-path optimization on hosted infrastructure offers the largest remaining opportunity to reduce latency at scale. We anticipate these baseline measurements will serve as a reference point for future digital twin projects evaluating whether Nexus’s latency profile meets their real-time requirements, and as a benchmark for tracking the effect of future infrastructure or API changes.

99 - GENERAL AND MISCELLANEOUS↗

Database-Agnostic Log Analysis and Monitoring Framework

Prior to my internship, I was informed that a previous intern had built a tool to analyse MongoDB logs and look for invalid access attempts, which served as a great reference point for my project. I was initially tasked with expanding on her prototype and filling in the gaps such as integrating it with the main monitoring tool the lab uses. Eventually, the scope grew, expanding to support other databases and a growing collection of tools. I organized the framework around an observer pattern, meaning one point in the program sending updates to the rest of the framework. Every time a log was read and parsed, it was sent to be processed by the tools, using the type of event as a means to determine which tools should get a chance to act on the log. This decouples the tools from the log reader, making future updates and additions much easier. The framework processes MongoDB logs at ~135,000 entries per second and PostgreSQL logs at ~170,500 entries per second, accurately detecting anomalies such as slow queries and connections from unknown addresses. This framework serves to fill gaps in database monitoring tools currently implemented at the lab, such as tracking failed authentication for PostgreSQL and MongoDB which had very minimal or none before this framework. National labs such as Fermilab hold sensitive data and valuable computing resources, making them attractive targets. Monitoring intrusion attempts on databases is made much easier by this comprehensive monitoring suite.

Clark, Dylan [Unlisted, US, IL; Fermilab]↗

Summary report on the enterprise security workshop

This report summarizes the presentations of the 7th IEEE Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprises (WETICE 2002) Enterprise Security (ES) Workshop.

software security cryptography authentication acce↗

WEDDS: The WITS Encrypted Data Delivery System

WEDDS, the WITS Encrypted Data Delivery System, is a framework for supporting distributed mission operations by automatically transferring sensitive mission data in a secure and efficient manner to and from remote mission participants over the internet.

public key cryptography encryption authentication ↗

Access Control of Web and Java Based Applications

Cyber security has gained national and international attention as a result of near continuous headlines from financial institutions, retail stores, government offices and universities reporting compromised systems and stolen data. Concerns continue to rise as threats of service interruption, and spreading of viruses become ever more prevalent and serious. Controlling access to application layer resources is a critical component in a layered security solution that includes encryption, firewalls, virtual private networks, antivirus, and intrusion detection. In this paper we discuss the development of an application-level access control solution, based on an open-source access manager augmented with custom software components, to provide protection to both Web-based and Java-based client and server applications.

cybersecurity↗

Final Technical Report

Explore the source record for details and available documents.

97 MATHEMATICS AND COMPUTING↗