Search NASA⌕ Search

SEARCH · Search NASA

Results for “software security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 325 records · Page 18

Summary of ADTT Website Functionality and Features

This report summarizes development of the ADTT web-based design environment by the ELORET team in 2000. The Advanced Design Technology Testbed had been in development for several years, with demonstration applications restricted to aerodynamic analyses of subsonic aircraft. The key changes achieved this year were improvements in Web-based accessibility, evaluation of collaborative visualization, remote invocation of geometry updates and performance analysis, and application to aerospace system analysis. Significant effort was also devoted to post-processing of data, chiefly through comparison of similar data for alternative vehicle concepts. Such comparison is an essential requirement for designers to make informed choices between alternatives. The next section of this report provides more discussion of the goals for ADTT development. Section 3 provides screen shots from a sample session in the ADTT environment, including Login and navigation to the project of interest, data inspection, analysis execution and output evaluation. The following section provides discussion of implementation details and recommendations for future development of the software and information technologies that provide the key functionality of the ADTT system. Section 5 discusses the integration architecture for the system, which links machines running different operating systems and provides unified access to data stored in distributed locations. Security is a significant issue for this system, especially for remote access to NAS machines, so Section 6 discusses several architectural considerations with respect to security. Additional details of some aspects of ADTT development are included in Appendices.

Hawke, Veronica↗

Software Defined Radio Architecture Contributions to Next Generation Space Communications

Space communications architecture concepts, comprising the elements of the system, the interactions among them, and the principles that govern their development, are essential factors in developing National Aeronautics and Space Administration (NASA) future exploration and science missions. Accordingly, vital architectural attributes encompass flexibility, the extensibility to insert future capabilities, and to enable evolution to provide interoperability with other current and future systems. Space communications architectures and technologies for this century must satisfy a growing set of requirements, including those for Earth sensing, collaborative observation missions, robotic scientific missions, human missions for exploration of the Moon and Mars where surface activities require supporting communications, and in-space observatories for observing the earth, as well as other star systems and the universe. An advanced, integrated, communications infrastructure will enable the reliable, multipoint, high-data-rate capabilities needed on demand to provide continuous, maximum coverage for areas of concentrated activity. Importantly, the cost/value proposition of the future architecture must be an integral part of its design; an affordable and sustainable architecture is indispensable within anticipated future budget environments. Effective architecture design informs decision makers with insight into the capabilities needed to efficiently satisfy the demanding space-communication requirements of future missions and formulate appropriate requirements. A driving requirement for the architecture is the extensibility to address new requirements and provide low-cost on-ramps for new capabilities insertion, ensuring graceful growth as new functionality and new technologies are infused into the network infrastructure. In addition to extensibility, another key architectural attribute of the space communication equipment's interoperability with other NASA communications systems, as well as those communications and navigation systems operated by international space agencies and civilian and government agencies. In this paper, we review the philosophies, technologies, architectural attributes, mission services, and communications capabilities that form the structure of candidate next-generation integrated communication architectures for space communications and navigation. A key area that this paper explores is from the development and operation of the software defined radio for the NASA Space Communications and Navigation (SCaN) Testbed currently on the International Space Station (ISS). Evaluating the lessons learned from development and operation feed back into the communications architecture. Leveraging the reconfigurability provides a change in the way that operations are done and must be considered. Quantifying the impact on the NASA Space Telecommunications Radio System (STRS) software defined radio architecture provides feedback to keep the standard useful and up to date. NASA is not the only customer of these radios. Software defined radios are developed for other applications, and taking advantage of these developments promotes an architecture that is cost effective and sustainable. Developments in the following areas such as an updated operating environment, higher data rates, networking and security can be leveraged. The ability to sustain an architecture that uses radios for multiple markets can lower costs and keep new technology infused.

Lessons Learned↗

Access Control of Web and Java Based Applications

Cyber security has gained national and international attention as a result of near continuous headlines from financial institutions, retail stores, government offices and universities reporting compromised systems and stolen data. Concerns continue to rise as threats of service interruption, and spreading of viruses become ever more prevalent and serious. Controlling access to application layer resources is a critical component in a layered security solution that includes encryption, firewalls, virtual private networks, antivirus, and intrusion detection. In this paper we discuss the development of an application-level access control solution, based on an open-source access manager augmented with custom software components, to provide protection to both Web-based and Java-based client and server applications.

cybersecurity↗

Cellulose molecular weight of corn stover with cotreatment

Here we present a dataset of cellulose molecular weights from corn stover after a cotreatment process. The corn stover sample was subjected to a combination of mechanical disruption (ball milling) and consolidated bioprocessing (CBP) process using the bacterium C. thermocellum at 60 grams/L solids loadings. Cellulose was isolated from control, no cotreatment control, and cotreatment corn stover. Cellulose was then derivatized using anhydrous pyridine and phenyl isocyanate over 48 h at 70 ºC. The reaction was quenched by anhydrous methanol. Methanol and water mixture (7:3, v/v) was added dropwise to promote precipitation of the cellulose derivative. The solids were collected by filtration and thoroughly washed with the methanol and water mixture followed by water. The cellulose derivative was dried overnight under vacuum at 40°C. The obtained cellulose tricarbanilates was then dissolved in tetrahydrofuran (THF) at 1.0 mg/mL and the solution was filtered through a 0.45 µm PTFE filter and placed in an auto-sampler vial. The molecular weight of cellulose was measured by Agilent GPC SECurity 1200 system equipped with four Waters Styragel columns (i.e., HR0.5, HR2, HR4, and HR6) and a UV detector (270 nm). THF was used as the mobile phase. Data collection and processing was performed by Polymer Standards Service WinGPC Unity software (Build 6807). The molecular weight was calculated relative to the polystyrene calibration curve. The data on molecular weights provided information about the effects of cotreatment on corn stover cellulose molecular changes.

Cellulose, molecular weights, corn stover, cotreat↗

Elucidator

SAND2025-01917O Elucidator is a software tool that allows for the storage and interpretation of arbitrary metadata for use in an HPC context. It provides a flexible specification of data members uses facilities to convert buffers of information into the appropriate data types to ensure type safety. The software supports multithreading and database support. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Teves, Joshua↗

Zero Order Reactioin Kinetics: Enabling the use of Detailed Chemical Kinetics in Combustion Simulations (Final CRADA Report)

This was a collaborative effort between Lawrence Livermore National Security, LLC (LLNS), as manager and operator of Lawrence Livermore National Laboratory (LLNL) and Gamma Technologies, LLC (GT or Participante), to incorporate the ability to access LLNL chemical kinetics technologies while using GT-SUITE, GT’s market leading engine simulation software. At the end of the project, LLNL has released Zero-RK version 3.5 with zero- and one-dimensional (0-D and 1-D) solver functionality that interfaces with GT’s GT-SUITE v2023 and later releases. GT has tested its product to assure their customers that the interface can provide reduction in chemistry solution time for detailed chemistry simulations. The process has also positioned GT to easily benefit from future improvements of the Zero-RK suite of tools developed under the DOE Vehicle Technologies Office.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH↗

Runway Safety Monitor Algorithm for Single and Crossing Runway Incursion Detection and Alerting

The Runway Safety Monitor (RSM) is an aircraft based algorithm for runway incursion detection and alerting that was developed in support of NASA's Runway Incursion Prevention System (RIPS) research conducted under the NASA Aviation Safety and Security Program's Synthetic Vision System project. The RSM algorithm provides warnings of runway incursions in sufficient time for pilots to take evasive action and avoid accidents during landings, takeoffs or when taxiing on the runway. The report documents the RSM software and describes in detail how RSM performs runway incursion detection and alerting functions for NASA RIPS. The report also describes the RIPS flight tests conducted at the Reno/Tahoe International Airport (RNO) and the Wallops Flight Facility (WAL) during July and August of 2004, and the RSM performance results and lessons learned from those flight tests.

Green, David F., Jr.↗

SANSMIC v.1.0

SAND2024-01036O The updated Sandia Solution Mining Code (SANSMIC) modeling software models the dissolution of underground salt cavern walls due to raw-water injection (leaching), assuming an oil blanket. A previous version of this software modeled the impacts of leaching at the Strategic Petroleum Reserve and has been used in research for several decades, but the source code was not available. The new version will enhance current research as additional subsurface storage of energy in solution-mined caverns increases. It will also allow research reproducibility by making the software available to the wider research community. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Hart, David↗

Fermilab s Transition to Token Authentication

Fermilab is the first High Energy Physics institution to transition from X.509 user certificates to authentication tokens in production systems. All of the experiments that Fermilab hosts are now using JSON Web Token (JWT) access tokens in their grid jobs. Many software components have been either updated or created for this transition, and most of the software is available to others as open source. The tokens are defined using the WLCG Common JWT Profile. Token attributes for all the tokens are stored in the Fermilab FERRY system which generates the configuration for the CILogon token issuer. High security-value refresh tokens are stored in Hashicorp Vault configured by htvault-config, and JWT access tokens are requested by the htgettoken client through its integration with HTCondor. The Fermilab job submission system jobsub was redesigned to be a lightweight wrapper around HTCondor. For automated job submissions a managed tokens service was created to reduce duplication of effort and knowledge of how to securely keep tokens active. The existing Fermilab file transfer tool ifdh was updated to work seamlessly with tokens, as well as the Fermilab POMS (Production Operations Management System) which is used to manage automatic job submission and the RCDS (Rapid Code Distribution System) which is used to distribute analysis code via the CernVM FileSystem. The dCache storage system was reconfigured to accept tokens for authentication in place of X.509 proxy certificates. As some services and sites have not yet implemented token support, proxy certificates are still sent with jobs for backwards compatibility but some experiments are beginning to transition to stop using them. There have been some glitches and learning curve issues but in general the system has been performing well and is being improved as operational problems are addressed.

Dykstra, David↗

Integrated Modeling, Mapping, and Simulation (IMMS) Framework for Exercise and Response Planning

EmergenCy management personnel at federal, stale, and local levels can benefit from the increased situational awareness and operational efficiency afforded by simulation and modeling for emergency preparedness, including planning, training and exercises. To support this goal, the Department of Homeland Security's Science & Technology Directorate is funding the Integrated Modeling, Mapping, and Simulation (IMMS) program to create an integrating framework that brings together diverse models for use by the emergency response community. SUMMIT, one piece of the IMMS program, is the initial software framework that connects users such as emergency planners and exercise developers with modeling resources, bridging the gap in expertise and technical skills between these two communities. SUMMIT was recently deployed to support exercise planning for National Level Exercise 2010. Threat, casualty. infrastructure, and medical surge models were combined within SUMMIT to estimate health care resource requirements for the exercise ground truth.

Mapar, Jalal↗

Prognostics As-A-Service (PaaS)

Deep awareness of aircraft system health-state is critical for maintaining safe, efficient growth in global operations and enabling autonomy. Maintainers, operators, controllers, dispatchers, pilots, and autonomous systems must have reliable real-time predictions of vehicle health to preserve safety and efficiency. We will explore the feasibility and challenges of cloud enhanced prognostics. Aircraft request PaaS in flight to supplement onboard systems or provide complete health awareness. We will explore and demonstrate the ability to address six major challenges of PaaS: Generality, Environmental Complexity, Utility, Trust, Communications, and Security. We will also explore the factors in the decision to host prognostics onboard vs As-A-Service.

Prognostics As A Service↗

DRF: A Software Architecture for a Data Marketplace to Support Advanced Air Mobility

Advanced Air Mobility is a new aviation vision, where unmanned aerial systems will trans- port passengers and cargo across urban and rural areas. Critical to the realization of this vision is the development of a digital marketplace, which allows service providers and consumers operating in the airspace ecosystem to securely exchange data and reasoning insights. In this paper, we present the architecture of a decentralized data marketplace that connects data and reasoning service providers to vehicles and other service consumers along the cloud-to-edge continuum. We also present two example use cases to demonstrate the value of our approach.

Autonomy↗

Fermilab's Transition to Token Authentication

Fermilab is the first High Energy Physics institution to transition from X.509 user certificates to authentication tokens in production systems. All the experiments that Fermilab hosts are now using JSON Web Token (JWT) access tokens in their grid jobs. Many software components have been either updated or created for this transition, and most of the software is available to others as open source. The tokens are defined using the WLCG Common JWT Profile. Token attributes for all the tokens are stored in the Fermilab FERRY system which generates the configuration for the CILogon token issuer. High security-value refresh tokens are stored in Hashicorp Vault configured by htvault-config, and JWT access tokens are requested by the htgettoken client through its integration with HTCondor. The Fermilab job submission system jobsub was redesigned to be a lightweight wrapper around HTCondor. The grid workload management system GlideinWMS which is also based on HTCondor was updated to use tokens for pilot job submission. For automated job submissions a managed tokens service was created to reduce duplication of effort and knowledge of how to securely keep tokens active. The existing Fermilab file transfer tool ifdh was updated to work seamlessly with tokens, as well as the Fermilab POMS (Production Operations Management System) which is used to manage automatic job submission and the RCDS (Rapid Code Distribution System) which is used to distribute analysis code via the CernVM FileSystem. The dCache storage system was reconfigured to accept tokens for authentication in place of X.509 proxy certificates. As some services and sites have not yet implemented token support, proxy certificates are still sent with jobs for backwards compatibility, but some experiments are beginning to transition to stop using them.

Dykstra, Dave [Fermilab] (ORCID:0000000326539015)↗

A Survey of Helium Accreting White Dwarfs

We have initiated a survey of the X-ray spectral properties of double white binaries using XMM-Newton. Three of our sources were indeed observed with XMM during AO-3. We have analyzed these data using the latest data reduction software and have also extracted several archival data sets of similar systems from the XMM archive. The first paper presenting the X-ray spectral and variability properties of four of these binary systems has been submitted in January 2005. We have also secured some optical ground-based spectroscopy and are currently analyzing the spectral signatures in more detail. We are also continuing this survey with additional approved XMM observations during AO-4 and anticipate additional publications in the near future.

Steeghs, Daniel↗

Scalable Asset Discovery, Vulnerability Scanning, and Penetration Testing for Remote Sites and Wireless Spectrums Utilizing an Embedded Linux Plug - PwniPlug and the Raspberry Pi B+ as a Sample Pen Test

All devices attached to the NASA KSC network are subject to security vulnerability scanning and/or penetration testing. In today's changing environment, vulnerable and/or unprotected systems can easily be overlooked. Systems that are not properly managed can become a potential threat to the operational integrity of our systems and networks. This includes all NASA (internal and external) information systems within NASA KSC Internet Protocol (IP) address space, and NASA KSC facilities. The Office of the Chief Information Officer (OCIO) recommends that all NASA Centers and information systems be subject to penetration testing on a regular interval in accordance with the guidelines identified by the National Institute of Standards and Technology (NIST). (ITS-HBK-2810.04-02A) Protecting information and equipment at NASA is an area of increasing concern. In addition to the CPU's on the network; Supervisory, Control and Data Acquisition (SCADA) systems are especially vulnerable because these systems have lacked standards, use embedded controllers with little computational power and informal software, are connected to physical processes, have few operators, and are increasingly also being connected to corporate networks. The scope of work is comprised of several individual components which together build upon previous work by Drew Branch, NASA KSC Intern. The Pwn Plug is the selected COTS (Commercial-Off-The-Shelf) device chosen to test simplification of mandatory IT Security tasks. The device will be utilized to provide services to NASA KSC and enable an assessment of infrastructure soundness and regulatory compliance in an efficient, economical, and business responsive manner. The Pwn Plug is designed as a pen testing appliance which provides a hardware platform that can support commercial penetration testing efforts at significantly reduced costs. The expected outcomes are: 1) External Penetration Testing, 2) Social Engineering, 3) Procedural Documentation, 4) Recommended Remediation Action Plan, 5) System Retest & Remediation Attestation and 6) Final Reports, out briefing and Presentation. Due to physical and material constraints beyond intern and mentor control, the project was redefined as a working pen-test scenario. Limitations of lab availability and tools dictated an academic exercise. This report was developed within the scenario guidelines suggested by the project mentor. The guidelines were to be creative in developing a Pen Test program for a client.

Penetration Testing↗

Real-Time Testbed for Smart Grid Recloser Controller

The growing need for a low voltage recloser has become apparent due to the rise in requirements for a smart grid. This includes more detailed management of power flow forward (towards load) and backward (towards generation), source synchronization in real time, more indepth fault responses, and the use of green energy. The SEL-651R-2 relay is a device that can manage these needs, especially in fault response and synchronization, and is commonly used in systems called microgrids. Microgrids are distribution level systems that are able to operate separated from the main grid, are typically installed much closer to the load(s), and are fed by distributed energy resources (DERs), such as wind, solar or diesel generators. The SEL-651R-2 is normally used in the field with presets operative settings, but the Western Michigan University (WMU) Center for Interdisciplinary Research on Secure, Efficient and Sustainable Energy Technology (WMU InterEnergy Center) wished to test this device in its range of capabilities for microgrid application. A Hardware-In-the-Loop (HIL) testbed was implemented and used through the Real Time Digital Simulator (RTDS) using the RSCAD software to test the SEL-651R-2's use cases and functions. The testbed includes a microgrid with interconnection to a larger main grid, and the relay is meant to control the recloser at the point of common coupling (PCC) between the main grid and microgrid. The testbed shows how basic protections, reclosing, and synchronization checks function when handling faults that affect both the microgrid and the main grid.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Lignin molecular weights of Populus trichocarpa residues after CELF pretreatment

Here we present a dataset of molecular weights of lignin from a woody energy crop (Populus trichocarpa) residues after a series of co-solvent enhanced lignocellulosic fractionation (CELF) pretreatment. The natural poplar variant GW-9947 from the Center for Bioenergy Innovation (CBI) was used. The poplar was knife milled and passed through a 1 mm sieve and CELF pretreatment was performed in a Parr autoclave reactor with 7.5 wt % solids loading, 0.5 wt% H2SO4 as catalyst at 150°C with various time. Tetrahydrofuran was added in a 1:1 mass ratio with water as the pretreatment solvent. Lignin was isolated from the pretreated samples after ball-milling in a porcelain jar with ceramic balls via Retsch PM 200 at 580 rpm for 2.5 h followed by enzymatic hydrolysis in acetate buffer (pH 4.8, 50 °C) for 48 h. The solid residue was isolated by centrifugation and hydrolyzed again with freshly added buffer and enzymes for another 48 h. After filtration, the solid residue was extracted twice with 96% (v/v) 1,4-dioxane/water mixture at room temperature overnight. The extracts were combined, rotary evaporated, and freeze-dried to recover lignin. The lignin samples were then derivatized in an acetic anhydride/pyridine (1:1, v/v) mixture and stirred at room temperature for 24 h. Ethanol was added to the reaction mixture, left for 30 min and then removed with a rotary evaporator. The addition and removal of ethanol was repeated at least 3 times until all traces of acetic acid were removed. Acetylated lignin samples were then dissolved in tetrahydrofuran (THF) at a concentration of 1.0 mg/mL. The molecular weight of acetylated lignin was measured by a gel permeation chromatography (GPC) on a PSS-Polymer Standards Service (Warwick, RI, USA) GPC SECurity 1200 system featuring Agilent HPLC 1200 components equipped with four Waters Styragel columns (HR1, HR2, HR4 and HR6) and an UV detector (270 nm). Tetrahydrofuran was used as the mobile phase and flow rate was 0.3 mL/min. The Polymer Standards Service WinGPC Unity software (Build 6807) was used for data processing for all the samples. The data provides information about the effects of CELF pretreatment time at 150 ºC on lignin molecular weights.

09 BIOMASS FUELS↗

GLobal Integrated Design Environment (GLIDE): A Concurrent Engineering Application

The GLobal Integrated Design Environment (GLIDE) is a client-server software application purpose-built to mitigate issues associated with real time data sharing in concurrent engineering environments and to facilitate discipline-to-discipline interaction between multiple engineers and researchers. GLIDE is implemented in multiple programming languages utilizing standardized web protocols to enable secure parameter data sharing between engineers and researchers across the Internet in closed and/or widely distributed working environments. A well defined, HyperText Transfer Protocol (HTTP) based Application Programming Interface (API) to the GLIDE client/server environment enables users to interact with GLIDE, and each other, within common and familiar tools. One such common tool, Microsoft Excel (Microsoft Corporation), paired with its add-in API for GLIDE, is discussed in this paper. The top-level examples given demonstrate how this interface improves the efficiency of the design process of a concurrent engineering study while reducing potential errors associated with manually sharing information between study participants.

McGuire, Melissa L.↗