Search NASASearch

SEARCH · Search NASA

Results for “authentication”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Spectroscopic investigation of cool giants and the authenticity of their reported microwave emission

Surface velocities and metal abundances for 19 red giant stars in the spectral range G5 to M3 are derived on the basis of AAT echelle spectroscopy data. Attention is given to the question of whether the stars reported to emit radio bursts had different physical properties (rotation rate, macroturbulence, microturbulence, and metal abundance) from those without the radio bursts, which might explain why they were radio emitters. The various velocities had values consistent with those previously found for other similar stars. There was an observed increase in both macroturbulent and, less definitely, microturbulent velocities with lateness of spectral type at K3 and later. A weak correlation between surface velocities and 8.4-GHz radio surface fluxes was found. No connection between iron abundances and radio surface fluxes was detected. It is concluded that few, if any, of the cool giants are radio emitters.

Jones, K. L.

Modeling Respiratory Toxicity of Authentic Lunar Dust

The lunar expeditions of the Apollo operations from the 60 s and early 70 s have generated awareness about lunar dust exposures and their implication towards future lunar explorations. Critical analyses on the reports from the Apollo crew members suggest that lunar dust is a mild respiratory and ocular irritant. Currently, NASA s space toxicology group is functioning with the Lunar Airborne Dust Toxicity Assessment Group (LADTAG) and the National Institute for Occupational Safety and Health (NIOSH) to investigate and examine toxic effects to the respiratory system of rats in order to establish permissible exposure levels (PELs) for human exposure to lunar dust. In collaboration with the space toxicology group, LADTAG and NIOSH the goal of the present research is to analyze dose-response curves from rat exposures seven and twenty-eight days after intrapharyngeal instillations, and model the response using BenchMark Dose Software (BMDS) from the Environmental Protection Agency (EPA). Via this analysis, the relative toxicities of three types of Apollo 14 lunar dust samples and two control dust samples, titanium dioxide (TiO2) and quartz will be determined. This will be executed for several toxicity endpoints such as cell counts and biochemical markers in bronchoaveolar lavage fluid (BALF) harvested from the rats.

Santana, Patricia A.

Addressing the Tension Between Strong Perimeter Control an Usability

This paper describes a strong perimeter control system for a general purpose processing system, with the perimeter control system taking significant steps to address usability issues, thus mitigating the tension between strong perimeter protection and usability. A secure front end enforces two-factor authentication for all interactive access to an enclave that contains a large supercomputer and various associated systems, with each requiring their own authentication. Usability is addressed through a design in which the user has to perform two-factor authentication at the secure front end in order to gain access to the enclave, while an agent transparently performs public key authentication as needed to authenticate to specific systems within the enclave. The paper then describes a proxy system that allows users to transfer files into the enclave under script control, when the user is not present to perform two-factor authentication. This uses a pre-authorization approach based on public key technology, which is still strongly tied to both two-factor authentication and strict control over where files can be transferred on the target system. Finally the paper describes an approach to support network applications and systems such as grids or parallel file transfer protocols that require the use of many ports through the perimeter. The paper describes a least privilege approach that dynamically opens ports on a host-specific, if-authorized, as-needed, just-in-time basis.

Hinke, Thomas H.

COnfirmation using Gamma-ray Non-Imaging Zero-knowledge ANti-mask Time-encoding (COGNIZANT) Final Summary Report

In potential future arms reduction treaties in which the numbers of nuclear warheads may approach small numbers, using delivery systems as a proxy for the warheads themselves may be insufficient. Therefore, a technical means of verifying the presence of a nuclear warhead may become necessary. Verifying that a declared item actually is a warhead is technically challenging within a verification regime: providing assurance to the monitoring party that a presented item is a warhead while protecting sensitive information about that warhead may be required. It is generally believed that strong assurance will require the confirmation of key attributes that may reveal closely-guarded critical design information. This provides high confidence to the monitoring party, but presents a risk of information loss to the host. A verification system must overcome this hurdle. Over the last several decades, systems have been developed that balance host and monitoring partner needs by using sensitive information to confirm treaty accountable items (TAI) as warheads while sequestering that information behind an information barrier (1). These are designed to meet the needs of the host but places the onus on the monitor to authenticate the hardware, firmware, and software. Authentication requires that the monitor confirm that all components of the system have not been modified and work as intended. In 2014, Glaser et al. proposed applying the concept of “zero knowledge protocols” (ZKP) from the field of cryptography to the problem of warhead verification (2). In mathematical cryptography, ZKP is accomplished by challenging one party to solve a problem that is only possible if that party possesses the information being authenticated. After repeated challenges, the party provides confidence that it possesses this information without revealing any details about the information itself. Systems have been in development based on this idea at both Princeton and MIT (2) (3) (4). The final measurement results produced by these systems can be viewed by both the host and the monitoring party without the worry of revealing sensitive information. However, in both of these physical implementations, there remains an information barrier within the system. The need for a digital information barrier to protect a measurement result is eliminated, but it has been replaced with the need to sequester physical components of the system, potentially obfuscating the measurement process itself. Both implementations physically insert information into the system that requires protection to prevent undesired disclosure of sensitive information: in the Princeton method, one must physically load the complement of the expected image of a true warhead into the system, and in the MIT technique, one loads a collection of spectator foils whose thicknesses physically encrypt a measured spectrum. This complicates authentication of the hardware and measurement process. The CONFIDANTE/COGNIZANT concept developed in this project do not load sensitive information into the system at any time, and could therefore open the possibility of allowing the inspector to not only view the final data but also the measurement as it is being performed and all associated equipment.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P

Bridging the Gap between Earth Science and Students: An Integrated Approach using NASA Earth Science Climate Data

Under the auspices of the Department of Education's No Child Left Behind (NCLB) Act, beginning in 2007 students will be tested in the science area. There are many techniques that educators can employ to teach students science. The use of authentic materials or in this case authentic data can be an engaging alternative to more traditional methods. An Earth science classroom is a great place for the integration of authentic data and science concepts. The National Aeronautics and Space Administration (NASA) has a wealth of high quality Earth science data available to the general public. For instance, the Atmospheric Science Data Center (ASDC) at NASA s Langley Research Center houses over 800 Earth science data sets related to Earth's radiation budget, clouds, aerosols and tropospheric chemistry. These data sets were produced to increase academic understanding of the natural and anthropogenic factors that influence global climate; however, a major hurdle in using authentic data is the size of the data and data documentation. To facilitate the use of these data sets for educational purposes, the Mentoring and inquirY using NASA Data on Atmospheric and Earth science for Teachers and Amateurs (MY NASA DATA) project has been established to systematically support educational activities at all levels of formal and informal education. The MY NASA DATA project accomplishes this by reducing these large data holdings to microsets that are easily accessible and explored by K-12 educators and students though the project's Web page. MY NASA DATA seeks to ease the difficulty in understanding the jargon-heavy language of Earth science. This manuscript will show how MY NASA DATA provides resources for NCLB implementation in the science area through an overview of the Web site, the different microsets available, the lesson plans and computer tools, and an overview of educational support mechanisms.

Alston, Erica J.

A Framework for Successful Research Experiences in the Classroom: Combining the Power of Technology and Mentors

Authentic research opportunities in the classroom are most impactful when they are student-driven and inquiry-based. These experiences are even more powerful when they involve technology and meaningful connections with scientists. In today's classrooms, activities are driven by state required skills, education standards, and state mandated testing. Therefore, programs that incorporate authentic research must address the needs of teachers. NASA's Expedition Earth and Beyond (EEAB) Program has developed a framework that addresses teacher needs and incorporates the use of technology and access to mentors to promote and enhance authentic research in the classroom. EEAB is a student involvement program that facilitates student investigations of Earth or planetary comparisons using NASA data. To promote student-led research, EEAB provides standards-aligned, inquiry-based curricular resources, an implementation structure to facilitate research, educator professional development, and ongoing support. This framework also provides teachers with the option to incorporate the use of technology and connect students with a mentor, both of which can enrich student research experiences. The framework is structured by a modeled 9-step process of science which helps students organize their research. With more schools gaining increased access to technology, EEAB has created an option to help schools take advantage of students' interest and comfort with technology by leveraging the use of available technologies to enhance student research. The use of technology not only allows students to collaborate and share their research, it also provides a mechanism for them to work with a mentor. This framework was tested during the 2010/2011 school year. Team workspaces hosted on Wikispaces for Educators allow students to initiate their research and refine their research question initially without external input. This allows teams to work independently and rely on the skills and interests of team members. Once teams finalize their research question, they are assigned a mentor. The mentor introduces himself/herself, acknowledges the initial work the team has conducted, and asks a focused question to help open the lines of communication. Students continue to communicate with their mentor throughout their research. As research is completed, teams can share their investigation during a virtual presentation. These live presentations allow students to share their research with their mentor, other scientists, other students, parents, and school administrators. After the initial year of testing this authentic research process, EEAB is working to address the many lessons learned. This will allow the program to refine and improve the overall process in an effort to maximize the benefits. Combined, these powerful strategies provide a successful framework to help teachers enhance the skills and motivation of their students, preparing them to become the next generation of scientists, explorers, and STEM-literate citizens of our nation.

Graff, Paige Valderrama

Non-nuclear Component Signatures for Warhead Dismantlement Confirmation

The verification of warhead dismantlement is expected to be an important component in future arms reduction treaties. Historic approaches developed with future arms control treaty verification in mind often involve intrusive measurements, process monitoring, and/or inspector presence to provide confidence that an authentic warhead has been dismantled. This work explores the possibility of reducing the negative impacts of these invasive approaches while also delivering a method that is more likely to provide non-sensitive data that can be shared with not only other nuclear weapons states but also non-nuclear weapons states partners. This work explores a novel approach for verifying dispositioned non-nuclear weapon components, providing confidence post-dismantlement that a treaty accountable item that was dismantled was in fact a treaty-relevant nuclear weapon system as declared. This method provides an alternative to intrusive inspection processes in nuclear weapons production environments, which would require significant changes to the host’s operational behaviors. It achieves this by identifying intrinsic neutron-induced signatures of non-nuclear components to determine their authenticity and estimate the duration they were exposed within a nuclear weapons system using technologies that are already in use for other national security applications. Intrinsic radiation effects studies are already a part of the stockpile aging and surveillance evaluations. However, none of these technologies and approaches have been previously considered for verification applications of non-nuclear component disposition. In this report, we introduce modeling studies that have been used to identify the most promising candidate parts and materials with signatures that are measurable and actionable. These models have been validated with laboratory measurements of signatures induced by the exposure of candidate materials to neutrons over a range of times. Predictive modeling then demonstrates the methodology for estimating exposure times and/or limits. Laboratory measurements of authentic non-nuclear parts from a dismantled warhead demonstrate the feasibility of employing these signature measurements. And finally, a concept of operations (CONOPS) for the potential use of this methodology is presented.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P

TrustDER: Trusted, Private and Scalable Coordination of Distributed Energy Resources

In this project, the Stanford and SLAC Teams have developed a Trusted, Private and Scalable platform for coordinating Coordination of Distributed Energy Resources (TrustDER). This is a layered system that ensures private, trusted and scalable coordination and monitoring of DERs. It accommodates a variety of resources, such as solar generation, gensets and loads, with a particular focus on battery systems-based resources, as they are a transformational technology experiencing fast growth in adoption by large critical facilities. The platform can be used as standalone or added to existing aggregation systems to enable trust, privacy and resilience. TrustDER consists of layers that address each of the shortcomings of the existing state of the art. Each layer in the platform can operate independently but provides information to the layers above it to enable a novel form of overall coordination architecture. The project consists of several tasks, with each task dedicated to the design of each layer. Task 2 Resource Virtualization defined a software abstraction layer for distributed energy resources (DERs). The goal of this abstraction was to simplify the implementation of algorithms utilizing cooperation of DERs resources in a variety of use cases. Task 3 is on Secure ID for Asset Authentication. Identity Management Systems (IDMS) are a foundational infrastructure for interactions between entities (organizations, users, devices, and services). Secure ID is blockchain-based a distributed identity management system allowing (1) identity provisioning, (2) authentication, (3) authorization, and (4) identity data sharing for IoT-enabled assets on the electricity grid. In this project, the SLAC team focused on designing and testing Keymaker, a protocol for authenticating device identity managed by Secure ID. Task 5 Private and Safe Integration is focused on the design and evaluation of a DER cooperation scheme which allows for the aggregation of DERs without impacting network reliability. The approach is designed based on realistic assumptions regarding data availability, communication infrastructure limitations, and privacy. Task 6 Scalable Distributed Privacy for Information explored how virtualized batteries could be managed privately. Specifically, it examined the case in which a principal provides a partitioned battery to multiple clients. Task 7 Use Cases was to ensure that this technology was applied in relevant situations and scenarios. Primarily, this means that virtualization needed to be employed in a manner that either improved flexibility, bolstered security or privacy, or decreased costs.

25 ENERGY STORAGE

Firmware Tampering Detection in Heavy-Duty Vehicles through J1939 CAN Analysis

Modern heavy-duty vehicles rely on complex networks of Electronic Control Units (ECUs) that communicate using the J1939 protocol. While this system makes it easier to update and configure vehicle components, it also opens the door to serious cybersecurity risks if not properly secured. This work investigates the potential for firmware tampering through the J1939 communication protocol, which enables ECU configuration and reprogramming over the Controller Area Network (CAN) bus. By monitoring CAN traffic during legitimate maintenance operations and reverse-engineering OEM diagnostic software, we identified common and proprietary J1939 message identifiers, authentication patterns, and vulnerabilities within Unified Diagnostic Services (UDS). These findings demonstrate that inadequate authentication mechanisms can allow malicious actors to alter ECU firmware or disable safety functions, posing severe operational and safety risks. Our analysis contributes to the development of vehicle intrusion detection systems capable of recognizing abnormal reprogramming activity and future firmware fingerprinting methods to verify software integrity across ECUs. This work highlights the importance of standardizing secure firmware authentication across manufacturers to strengthen cyber resilience in heavy-duty vehicle systems.

33 ADVANCED PROPULSION SYSTEMS

UNIX security in a supercomputing environment

The author critiques some security mechanisms in most versions of the Unix operating system and suggests more effective tools that either have working prototypes or have been implemented, for example in secure Unix systems. Although no computer (not even a secure one) is impenetrable, breaking into systems with these alternate mechanisms will cost more, require more skill, and be more easily detected than penetrations of systems without these mechanisms. The mechanisms described fall into four classes (with considerable overlap). User authentication at the local host affirms the identity of the person using the computer. The principle of least privilege dictates that properly authenticated users should have rights precisely sufficient to perform their tasks, and system administration functions should be compartmentalized; to this end, access control lists or capabilities should either replace or augment the default Unix protection system, and mandatory access controls implementing multilevel security models and integrity mechanisms should be available. Since most users access supercomputing environments using networks, the third class of mechanisms augments authentication (where feasible). As no security is perfect, the fourth class of mechanism logs events that may indicate possible security violations; this will allow the reconstruction of a successful penetration (if discovered), or possibly the detection of an attempted penetration.

Bishop, Matt

The trustworthy digital camera: Restoring credibility to the photographic image

The increasing sophistication of computers has made digital manipulation of photographic images, as well as other digitally-recorded artifacts such as audio and video, incredibly easy to perform and increasingly difficult to detect. Today, every picture appearing in newspapers and magazines has been digitally altered to some degree, with the severity varying from the trivial (cleaning up 'noise' and removing distracting backgrounds) to the point of deception (articles of clothing removed, heads attached to other people's bodies, and the complete rearrangement of city skylines). As the power, flexibility, and ubiquity of image-altering computers continues to increase, the well-known adage that 'the photography doesn't lie' will continue to become an anachronism. A solution to this problem comes from a concept called digital signatures, which incorporates modern cryptographic techniques to authenticate electronic mail messages. 'Authenticate' in this case means one can be sure that the message has not been altered, and that the sender's identity has not been forged. The technique can serve not only to authenticate images, but also to help the photographer retain and enforce copyright protection when the concept of 'electronic original' is no longer meaningful.

Friedman, Gary L.

Practical Computer Security through Cryptography

The core protocols upon which the Internet was built are insecure. Weak authentication and the lack of low level encryption services introduce vulnerabilities that propagate upwards in the network stack. Using statistics based on CERT/CC Internet security incident reports, the relative likelihood of attacks via these vulnerabilities is analyzed. The primary conclusion is that the standard UNIX BSD-based authentication system is by far the most commonly exploited weakness. Encryption of Sensitive password data and the adoption of cryptographically-based authentication protocols can greatly reduce these vulnerabilities. Basic cryptographic terminology and techniques are presented, with attention focused on the ways in which technology such as encryption and digital signatures can be used to protect against the most commonly exploited vulnerabilities. A survey of contemporary security software demonstrates that tools based on cryptographic techniques, such as Kerberos, ssh, and PGP, are readily available and effectively close many of the most serious security holes. Nine practical recommendations for improving security are described.

McNab, David

Preservation Environments

The long-term preservation of digital entities requires mechanisms to manage the authenticity of massive data collections that are written to archival storage systems. Preservation environments impose authenticity constraints and manage the evolution of the storage system technology by building infrastructure independent solutions. This seeming paradox, the need for large archives, while avoiding dependence upon vendor specific solutions, is resolved through use of data grid technology. Data grids provide the storage repository abstractions that make it possible to migrate collections between vendor specific products, while ensuring the authenticity of the archived data. Data grids provide the software infrastructure that interfaces vendor-specific storage archives to preservation environments.

Moore, Reagan W.