Search NASA⌕ Search

SEARCH · Search NASA

Results for “Secure by Design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

A model of security monitoring

A model of security monitoring is presented that distinguishes between two types of logging and auditing. Implications for the design and use of security monitoring mechanisms are drawn from this model. The usefulness of the model is then demonstrated by analyzing several different monitoring mechanisms.

Bishop, Matt↗

Analyzing the security of an existing computer system

Most work concerning secure computer systems has dealt with the design, verification, and implementation of provably secure computer systems, or has explored ways of making existing computer systems more secure. The problem of locating security holes in existing systems has received considerably less attention; methods generally rely on thought experiments as a critical step in the procedure. The difficulty is that such experiments require that a large amount of information be available in a format that makes correlating the details of various programs straightforward. This paper describes a method of providing such a basis for the thought experiment by writing a special manual for parts of the operating system, system programs, and library subroutines.

Bishop, M.↗

Requirements for a network storage service

Sandia National Laboratories provides a high performance classified computer network as a core capability in support of its mission of nuclear weapons design and engineering, physical sciences research, and energy research and development. The network, locally known as the Internal Secure Network (ISN), was designed in 1989 and comprises multiple distributed local area networks (LAN's) residing in Albuquerque, New Mexico and Livermore, California. The TCP/IP protocol suite is used for inner-node communications. Scientific workstations and mid-range computers, running UNIX-based operating systems, compose most LAN's. One LAN, operated by the Sandia Corporate Computing Directorate, is a general purpose resource providing a supercomputer and a file server to the entire ISN. The current file server on the supercomputer LAN is an implementation of the Common File System (CFS) developed by Los Alamos National Laboratory. Subsequent to the design of the ISN, Sandia reviewed its mass storage requirements and chose to enter into a competitive procurement to replace the existing file server with one more adaptable to a UNIX/TCP/IP environment. The requirements study for the network was the starting point for the requirements study for the new file server. The file server is called the Network Storage Services (NSS) and is requirements are described in this paper. The next section gives an application or functional description of the NSS. The final section adds performance, capacity, and access constraints to the requirements.

Kelly, Suzanne M.↗

Genomics and Proteomics Based Security Protocols for Secure Network Architectures

A hardware design that integrates live and algorithmic inhabitants to produce patterns of gene expression in vivo and in silico Protocols and algorithms based upon the processes of regulation of gene expression to produce cryptographic representations of genes, RNA, proteins, and gene expression to perform authentication and confidentiality functions for computers and networks. A network concept of operations integrating all of the above into existing legacy networks.

Security Genomics↗

R2U2: Monitoring and Diagnosis of Security Threats for Unmanned Aerial Systems

We present R2U2, a novel framework for runtime monitoring of security properties and diagnosing of security threats on-board Unmanned Aerial Systems (UAS). R2U2, implemented in FPGA hardware, is a real-time, REALIZABLE, RESPONSIVE, UNOBTRUSIVE Unit for security threat detection. R2U2 is designed to continuously monitor inputs from the GPS and the ground control station, sensor readings, actuator outputs, and flight software status. By simultaneously monitoring and performing statistical reasoning, attack patterns and post-attack discrepancies in the UAS behavior can be detected. R2U2 uses runtime observer pairs for linear and metric temporal logics for property monitoring and Bayesian networks for diagnosis of security threats. We discuss the design and implementation that now enables R2U2 to handle security threats and present simulation results of several attack scenarios on the NASA DragonEye UAS.

Formal Methods↗

Securing mechanism for the deployable column of the Hoop/Column antenna

The Column Longeron Latch (CLL) was designed and developed as the securing mechanism for the deployable, telescoping column of the Hoop/Column antenna. The column is an open lattice structure with three longerons as the principal load-bearing members. It is divided into telescoping sections that are deployed after the antenna is place in Earth orbit. The CLL provides a means to automatically lock the longeron sections into position during deployment as well as a means of unlocking the sections when the antenna is to be restowed. The CLL is a four bar linkage mechanism using the over center principle for locking. It utilizes the relative movement of the longeron sections to activate the mechanism during antenna deployment and restowing. The CLL design is one of the first mechanisms developed to meet the restowing requirements of spacecraft which will utilize the STS retrieval capability.

Ahl, E. L., Jr.↗

NASA Aeronautics Research Mission Directorate System Security Engineering Approaches

System security engineering (SSE) is a set of formal engineering methods and is considered a subset of systems engineering. It is a relatively new development in systems engineering with the initial NIST (National Institute of Standards) standard published in November of 2016 with updates in 2018, and 2022. The guiding principles in our methodology are based in NIST Special Publication 800-160 Vol. 1 “Systems Security Engineering: Considerations For A Multidisciplinary Approach In The Engineering Of Trustworthy Secure Systems” and integrate methodologies from common IT (Information Technology) threat modeling approaches utilizing MBSE (Model-Based Systems Engineering). The presentation will discuss how our teams utilize SSE and MBSE (Model-Based Systems Engineering) to develop secure architectures for systems under development in our NASA aeronautics research environment. This includes the activities to develop Protection Needs (PN) that, in turn result in security requirements in the design context and policies for the future state operational context for system protection. The process of applying SSE to analyze project architectures and ConOps (Concept of Operations) is intended to ensure the transferred research is both secure and securable in a “real-world” setting.

Systems Security Engineering↗

Security System Software

C Language Integration Production System (CLIPS), a NASA-developed expert systems program, has enabled a security systems manufacturer to design a new generation of hardware. C.CURESystem 1 Plus, manufactured by Software House, is a software based system that is used with a variety of access control hardware at installations around the world. Users can manage large amounts of information, solve unique security problems and control entry and time scheduling. CLIPS acts as an information management tool when accessed by C.CURESystem 1 Plus. It asks questions about the hardware and when given the answer, recommends possible quick solutions by non-expert persons.

Source record↗

Safe Grid

The biggest users of GRID technologies came from the science and technology communities. These consist of government, industry and academia (national and international). The NASA GRID is moving into a higher technology readiness level (TRL) today; and as a joint effort among these leaders within government, academia, and industry, the NASA GRID plans to extend availability to enable scientists and engineers across these geographical boundaries collaborate to solve important problems facing the world in the 21 st century. In order to enable NASA programs and missions to use IPG resources for program and mission design, the IPG capabilities needs to be accessible from inside the NASA center networks. However, because different NASA centers maintain different security domains, the GRID penetration across different firewalls is a concern for center security people. This is the reason why some IPG resources are been separated from the NASA center network. Also, because of the center network security and ITAR concerns, the NASA IPG resource owner may not have full control over who can access remotely from outside the NASA center. In order to obtain organizational approval for secured remote access, the IPG infrastructure needs to be adapted to work with the NASA business process. Improvements need to be made before the IPG can be used for NASA program and mission development. The Secured Advanced Federated Environment (SAFE) technology is designed to provide federated security across NASA center and NASA partner's security domains. Instead of one giant center firewall which can be difficult to modify for different GRID applications, the SAFE "micro security domain" provide large number of professionally managed "micro firewalls" that can allow NASA centers to accept remote IPG access without the worry of damaging other center resources. The SAFE policy-driven capability-based federated security mechanism can enable joint organizational and resource owner approved remote access from outside of NASA centers. A SAFE enabled IPG can enable IPG capabilities to be available to NASA mission design teams across different NASA center and partner company firewalls. This paper will first discuss some of the potential security issues for IPG to work across NASA center firewalls. We will then present the SAFE federated security model. Finally we will present the concept of the architecture of a SAFE enabled IPG and how it can benefit NASA mission development.

Chow, Edward T.↗

NASA's Photon-Counting SLR2000 Satellite Laser Ranging System: Progress and Applications

NASA's new unmanned SLR2000 system is designed to track, with millimeter precision and using single photon returns, a constellation of roughly 24 retroreflector-equipped satellites, which range in altitude from about 300 km to 20,000 km. Totally autonomous operation and a common engineering configuration are expected to greatly reduce station operations costs relative to NASA's current manned systems. The system has also been designed with a goal of significantly lowering replication costs. All of the prototype components and subsystems have been completed and tested and have substantially met the original specifications. The prototype system is presently undergoing final integration and testing in a dedicated shelter with an azimuth tracking dome synchronized to the optical tracking mount. The facility also features a number of security features such as security cameras and sensors designed to detect power or thermal control problems or entry by unauthorized personnel. Field tests are in progress. The present paper provides an overview of the various subsystems and test results to date. The meteorological subsystem, which has operated successfully in the field for almost three years, consists of several sensors which measure: (1) pressure, temperature, and relative humidity; (2) wind speed and direction; (3) ground visibility and precipitation; and (4) local cloud cover as a function of station azimuth and elevation (day and night). A "pseudo-operator" software program interprets the sensor readings and modifies satellite tracking priorities based on local meteorological conditions.

Degnan, John J.↗

Laboratory Tool

Veterans Administration medical researchers, along with Langley Research Center are investigating possibility that peritoneal membrane (lining of abdominal cavity) can absorb nutrients and thus provide alternative route for nutrition when intestinal function is impaired. Apparatus (cake box design) consists of octagonal chamber with eight smaller chambers attached and secured by O-ring seals. Design is simple, interchangeable, and time controllable.

Source record↗

High-Altitude ADS-B/GPS LPV Flight Tests on a NASA ER-2 Research Airplane

The research presented in this paper describes the conceptual design of a system architecture that integrates Automatic Dependent Surveillance-Broadcast (ADS-B) and Global Positioning System (GPS) Localizer Performance Vertical (LPV) guidance technology onto a unique high-altitude research airplane: a United States Air Force (USAF) / Lockheed Martin (Bethesda, Maryland) Aeronautics U-2S airplane. The design features modern display capabilities to provide air-to-air surveillance and precision navigation, to adhere to Federal Aviation Administration (FAA) certification standards for operations in upper Class E airspace. The National Aeronautics and Space Administration (NASA) variant of the U-2S, now called the Earth Resources (ER-2) airplane, remains unrivaled in the art of sustained high-altitude flight for scientific expeditions. Capable of routinely cruising above flight level (FL) 650 that had been considered, at inception, the domain of only the most elite experimental research aircraft types. Nicknamed the Dragon Lady, this U-2S research testbed is still one of the most advanced aircraft in the world. The exceptional military design of the vehicle, security guidelines, and the performance envelope of the ER-2 posed unique challenges to the integration of modern civilian avionics. ADS-B epitomizes the next generation of surveillance technology, incorporating both air and ground aspects. ADS-B provides air traffic control (ATC) with a more accurate picture of the three-dimensional positioning of aircraft in various phases of flight, including en route, terminal, approach, and ground operations. The airborne surveillance system broadcasts its identification, position, altitude, velocity, and other information. GPS LPV represents a significant advancement in aviation technology, emphasizing the pivotal role that GPS and Performance-Based Navigation concepts will play in the foreseeable future. This technology represents a shift from sensor-based navigation to performance-based navigation, allowing for more flexible and efficient use of airspace. This research described herein is structured as follows: Section II, “Systems Background,” provides a systems background and description of an ADS-B and GPS LPV system equipped on the high-altitude ER-2 research airplane to satisfy the FAA airworthiness requirements for high-altitude flight operations. Section III, “Flight Test System,” describes the flight-test airplane systems. Section IV, “Analysis of GPS SBAS, Safety, and Ground Tests,” provides an overview of the GPS Satellite-Based Augmentation System (SBAS) and an analysis of the GPS LPV metrics, safety, and ground tests. Section V, “High-Altitude Flight Tests,” describes the high-altitude flight tests, including 3 flight-test results, analysis, human factors, and lessons learned. Section VI, the conclusion, draws insights from the lessons learned, discusses the design challenges associated with ADS-B and GPS LPV, and showcases the paramount significance of these pivotal technologies in aircraft surveillance and navigation.

Ricardo A. Arteaga↗

Test stand for Titan 34D SRM static firing

An existing liquid engine test stand at the AF Astronautics Laboratory was refurbished and extensively modified to accommodate the static firing of the Titan 34D solid rocket motor (SRM) in the vertical nozzle down orientation. The main load restraint structure was designed and built to secure the SRM from lifting off during the firing. In addition, the structure provided weather protection, temperature conditioning of the SRM, and positioning of the measurement and recording equipment. The structure was also used for stacking/de-stacking of SRM segments and other technological processes. The existing stand, its foundation and anchorage were thoroughly examined and reanalyzed. Necessary stand modifications were carried out to comply with the requirements of the Titan 34D SRM static firing.

Glozman, Vladimir↗

Architecture for Survivable System Processing (ASSP)

The Architecture for Survivable System Processing (ASSP) Program is a multi-phase effort to implement Department of Defense (DOD) and commercially developed high-tech hardware, software, and architectures for reliable space avionics and ground based systems. System configuration options provide processing capabilities to address Time Dependent Processing (TDP), Object Dependent Processing (ODP), and Mission Dependent Processing (MDP) requirements through Open System Architecture (OSA) alternatives that allow for the enhancement, incorporation, and capitalization of a broad range of development assets. High technology developments in hardware, software, and networking models, address technology challenges of long processor life times, fault tolerance, reliability, throughput, memories, radiation hardening, size, weight, power (SWAP) and security. Hardware and software design, development, and implementation focus on the interconnectivity/interoperability of an open system architecture and is being developed to apply new technology into practical OSA components. To insure for widely acceptable architecture capable of interfacing with various commercial and military components, this program provides for regular interactions with standardization working groups (e.g.) the International Standards Organization (ISO), American National Standards Institute (ANSI), Society of Automotive Engineers (SAE), and Institute of Electrical and Electronic Engineers (IEEE). Selection of a viable open architecture is based on the widely accepted standards that implement the ISO/OSI Reference Model.

Wood, Richard J.↗

Development of Experiment Kits for Processing Biological Samples In-Flight on SLS-2

The design of the hematology experiment kits for SLS-2 has resulted in a modular, flexible configuration which maximizes crew efficiency and minimizes error and confusion when dealing with over 1200 different components over the course of the mission. The kit layouts proved to be very easy to use and their packaging design provided for positive, secure containment of the many small components. The secondary Zero(Tm) box enclosure also provided an effective means for transport of the kits within the Spacelab and for grouping individual kits by flight day usage. The kits are readily adaptable to use on future flights by simply replacing the inner components as required and changing the labelling scheme to match new mission requirements.

Jaquez, R.↗

Antiterrorist Software

In light of the escalation of terrorism, the Department of Defense spearheaded the development of new antiterrorist software for all Government agencies by issuing a Broad Agency Announcement to solicit proposals. This Government-wide competition resulted in a team that includes NASA Lewis Research Center's Computer Services Division, who will develop the graphical user interface (GUI) and test it in their usability lab. The team launched a program entitled Joint Sphere of Security (JSOS), crafted a design architecture (see the following figure), and is testing the interface. This software system has a state-ofthe- art, object-oriented architecture, with a main kernel composed of the Dynamic Information Architecture System (DIAS) developed by Argonne National Laboratory. DIAS will be used as the software "breadboard" for assembling the components of explosions, such as blast and collapse simulations.

Clark, David A.↗

Facility Upgrade/Replacement Tasks ('planned') at the NASA Glenn Research Center 10x10 Supersonic Wind Tunnel

Facility upgrades and large maintenance tasks needed at the NASA Glenn 10x10 Supersonic Wind Tunnel requires significant planning to make sure implementation proceeds in an efficiently and cost effective manner. Advanced planning to secure the funding, complete design efforts and schedule the installation needs to be thought out years in advance to avoid interference with wind tunnel testing. This presentation describes five facility tasks planned for implementation over the next few years. The main focus of the presentation highlights the efforts on possible replacement of the diesel generator and the rationale behind the effort.

Giriunas, Julius A.↗

Curating NASA's Past, Present, and Future Extraterrestrial Sample Collections

As codified in NASA Policy Directive 7100.10F, the Astromaterials Acquisition and Curation Office at NASA Johnson Space Center (hereafter JSC Curation) is charged with curation of all extraterrestrial material under NASA control, including future NASA missions. JSC Curation curates all or part of nine astromaterial collections in seven clean room suites: (1) Apollo Samples (1969; ISO 6-7), (2) Luna Samples (from USSR; 1972; ISO 7), (3) Antarctic Meteorites (1976; ISO 7), (4) Cosmic Dust (1981; ISO 5), (5) Microparticle Impact Collection (formerly called Space Exposed Hardware; 1985; ISO 5), (6) Genesis Solar Wind Atoms (2004; ISO 4); (7) Stardust Comet Particles (2006; ISO 5), (8) Stardust Interstellar Particles (2006; ISO 5), (9) Hayabusa Asteroid Particles (from JAXA; 2010; ISO 5). In addition to the labs that house the samples, we have installed and maintained a wide variety of facilities and infrastructure required to support the clean-rooms: more than 10 different HEPA-filtered air-handling systems, ultrapure dry gaseous nitrogen systems, an ultrapure water system (UPW) and cleaning facilities to provide clean tools and equipment for the labs. We also have sample preparation facilities for making thin sections, microtome sections, and even focused ion-beam (FIB) sections to meet the research requirements of scientists. To ensure that we are keeping the samples as pristine as possible, we routinely monitor the cleanliness of our clean rooms and infrastructure systems. This monitoring includes: daily monitoring of the quality of our UPW, weekly airborne particle counts in the labs, monthly monitoring of the stable isotope composition of the gaseous N2 system, and annual measurements of inorganic or organic contamination in processing cabinets. We track within our databases the current and ever-changing characteristics of more than 250,000 individual samples across our various collections (including the 19,141 samples on loan to 433 Principal Investigators in 24 countries). The next sample return missions that NASA will participate in are Hayabusa2 and OSIRIS-REx (Origins Spectral Interpretation Resource Identification Security - Regolith Explorer). The designs for a new state-of-the-art suite of clean rooms to house these samples at JSC have been finalized. This includes separate ISO class 5 clean rooms to house each collection, a common ISO class 7 area for general use, an ISO class 7 microtome laboratory, and a separate thin section lab. Additionally, a new cleaning facility is being designed and procedures developed that will allow for enhanced cleaning of cabinets and tools in an inorganically, organically, and biologically clean manner. We are also designing a large multi-purpose Advanced Curation laboratory that will allow us to develop the techniques necessary to fully support the Hayabusa2 and OSIRIS-REx missions, as well as future possible sample return missions (e.g., Lunar Polar Volatiles, Mars, Comet Surface). A micro-CT (micro Computed Tomography) laboratory dedicated to the study of astromaterials has come online within JSC Curation, and we plan to add additional facilities that will enable non-destructive (or minimally-destructive) analyses of astromaterials in the near future (e.g., micro-XRF (micro X-Ray Fluorescence), confocal imaging Raman Spectroscopy). These facilities will be available to: (1) develop sample handling and storage techniques for future sample return missions, (2) be utilized by PET (Positron Emission Tomography) for future sample return missions, (3) for retroactive PET-style analyses of our existing collections, and (4) for periodic assessments of the existing sample collections.

Zeigler, Ryan A.↗