Search NASASearch

SEARCH · Search NASA

Results for “authentication”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

WLCG transition from X.509 to Tokens: Progress and Outlook

Since 2017, the Worldwide LHC Computing Grid (WLCG) has been working towards enabling token-based authentication and authorization throughout its entire middleware stack.Taking guidance from the WLCG Token Transition Timeline, published in 2022, substantial progress has been achieved not only in making middleware compatible with the use of tokens, but also in understanding the limitations of the WLCG Common JWT Profiles, first published in 2019. Significant scalability experience has been gained from Data Challenge 2024, during which millions of files were transferred with tokens used as credentials - a significant percentage of the total transfers completed.Besides describing the state of affairs in the transition to tokens, revisions to the WLCG token profile, and the evolving road maps, this contribution also covers the corresponding transition from VOMS-Admin to INDIGO-IAM services, with continuing improvements in terms of functionality as well as deployment.

Dack, Thomas [Rutherford Appleton Laboratory]

Gcn2 structurally mimics and functionally repurposes the HisRS enzyme for the integrated stress response

Protein kinase Gcn2 attenuates protein synthesis in response to amino acid starvation while stimulating translation of a transcriptional activator of amino acid biosynthesis. Gcn2 activation requires a domain related to histidyl-tRNA synthetase (HisRS), the enzyme that aminoacylates tRNA His . While evidence suggests that deacylated tRNA binds the HisRS domain for kinase activation, ribosomal P-stalk proteins have been implicated as alternative activating ligands on stalled ribosomes. We report crystal structures of the HisRS domain ofChaetomium thermophilumGcn2 that reveal structural mimicry of both catalytic (CD) and anticodon-binding (ABD) domains, which in authentic HisRS bind the acceptor stem and anticodon loop of tRNA His . Elements for forming histidyl adenylate and aminoacylation are lacking, suggesting that Gcn2 HisRS was repurposed for kinase activation, consistent with mutations in the CD that dysregulate yeast Gcn2 function. Substituting conserved ABD residues well positioned to contact the anticodon loop or that form a conserved ABD–CD interface impairs Gcn2 function in starved cells. Mimicry in Gcn2 HisRS of two highly conserved structural domains for binding both ends of tRNA—each crucial for Gcn2 function—supports that deacylated tRNAs activate Gcn2 and exemplifies how a metabolic enzyme is repurposed to host new local structures and sequences that confer a novel regulatory function.

Science & Technology - Other Topics

Demonstration and Concept of Operations for a Zero-Knowledge Protocol Passive Imaging Measurement for Arms Control

Here, we present an imaging system that employs zero-knowledge protocols to protect sensitive geometrical information, along with procedures to increase confidence in the result. The goal of this work is to enable the inclusion of warhead confirmation measurements in future arms control treaties. We present a demonstration of both true positive and true negative measurements that validate models and establish authenticating procedures toward meeting acceptance requirements for use in nuclear facilities. We use a two-dimensional time-encoded fast neutron imaging system with an anti-symmetric mask pattern; the fast neutron count values exceeding minimum or maximum thresholds indicate that two measured items are not identical. Laboratory measurements over twenty trials show that alarm rates for negative confirmation measurements are within uncertainties of model predictions. Positive confirmation measurements indicate that alarm rates are large enough to encourage treaty compliance.

Sweany, Melinda Dominique [Sandia National Laborat

Beyond Solanaceae: incorporation of feruloyltyramine and feruloyloctopamine into Cannabaceae lignins

The ferulic acid amides, feruloyltyramine and feruloyloctopamine, have been widely reported as integral constituents in the lignins in several species of Solanaceae in which they function as authentic lignin monomers. In the present study, we demonstrate that these ferulic acid amides are likewise incorporated into the lignins of species within Cannabaceae, including hemp (Cannabis sativa), hops (Humulus lupulus), and European nettle tree (Celtis australis). Structural analyses using derivatization followed by reductive cleavage (DFRC) and two-dimensional nuclear magnetic resonance (2D-NMR) spectroscopy revealed that these ferulic acid amides are incorporated via 4−O- and 8−O-ether linkages, as well as through 8−5′ linkages forming phenylcoumaran structures. Examination of a broad phylogenetic range of plant families demonstrated the absence of these ferulic acid amides from the lignins of all families studied except Solanaceae and Cannabaceae. Given the distant phylogenetic relationship between Solanaceae and Cannabaceae, the recruitment of these ferulic acid amides as lignin monomers in both lineages likely constitutes a case for convergent evolution at the level of lignin biosynthetic pathways. The significance of these ferulic acid amides lies in their unique role as the sole nitrogen-containing phenolic compounds known to participate in lignin formation.

Cannabaceae

Orbital Ingredients and Persistent Dirac Surface State for the Topological Band Structure in FeTe 0.55 Se 0.45

FeTe 0.55 Se 0.45 (FTS) occupies a special spot in modern condensed matter physics at the intersections of electron correlation, topology, and unconventional superconductivity. The bulk electronic structure of FTS is predicted to be topologically nontrivial due to the band inversion between the d x z and p z bands along Γ − Z . However, there remain debates in both the authenticity of the Dirac surface states (DSSs) and the experimental deviations of band structure from the theoretical band inversion picture. Here we resolve these debates through a comprehensive angle-resolved photoemission spectroscopy investigation. We first observe a persistent DSS independent of k z . Then, by comparing FTS with FeSe, which has no band inversion along Γ − Z , we identify the spectral weight fingerprint of both the presence of the p z band and the inversion between the d x z and p z bands. Furthermore, we propose a renormalization scheme for the band structure under the framework of a tight-binding model preserving crystal symmetry. Our results highlight the significant influence of correlation on modifying the band structure and make a strong case for the existence of topological band structure in this unconventional superconductor. Published by the American Physical Society 2024

75 CONDENSED MATTER PHYSICS, SUPERCONDUCTIVITY AND

Nuclear Quadrupole Resonance for Substance Detection

This review paper provides a comprehensive overview of recent advances in nuclear quadrupole resonance (NQR) spectroscopy for substance detection, highlighting its principles, methodologies, and applications. The paper elucidates the fundamental physics underlying NQR spectroscopy, emphasizing the interaction between nuclear quadrupole moments and electric field gradients. It explores the various experimental techniques and instrumentation developments that have enabled the sensitive detection and precise characterization of substances containing quadrupolar nuclei. A significant portion of the survey is dedicated to discussing the diverse applications of NQR spectroscopy, including the detection of explosives, drug pharmaceuticals, and material authentication. Furthermore, the survey examines the challenges and limitations associated with NQR spectroscopy, including issues related to signal-to-noise ratio (SNR), temperature dependency, and substance restrictions. Strategies to overcome these challenges are discussed, offering insights into the future directions of NQR spectroscopy research that includes artificial intelligence (AI), internet of things (IoT) integration, incorporating a cloud database for NQR parameter storage, and multi-modal analysis.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND

Rapid Event Detection via Synchro-Waveform Based Temporal Attention Network in Distributed Grid

Compared with the information collected from phasor measurement units, synchro-waveforms contain high-fidelity disturbances of the grid, which can be a granular and authentic representation of measurements in the modern power system. However, the dynamic changing morphology makes it challenging to effectively capture various disturbance information from the synchro-waveforms. To tackle this issue, this paper proposes a Synchro-waveform based Temporal Attention (STA) network to achieve rapid event detection. First, a multi-scenario distributed model with renewable integration is established to generate synchro-waveforms under various uncertainties. Then, three typical temporal features are extracted directly from the synchro-waveform measurements. Additionally, the lightweight STA network is deployed to identify the most common event types in renewable energy systems via the self-attention based vision transformer module. The results from simulated experiments demonstrate that the proposed approach can achieve rapid and real-time detection within 0.81 ms and over 96.27 % accuracy.

Dong, Yuqing [University of Tennessee (UT)]

Integrating AEAD Ciphers into Software-Defined-Storage Systems

The use of software-defined storage (SDS) systems to store sensitive data is becoming increasingly prevalent. However, these systems primarily implement security measures to ensure the confidentiality and availability of stored data, with limited consideration for the protection of its integrity. This paper outlines why this is a harmful development, as well as how integrity-protecting measures can be included into SDS systems. To demonstrate the practical challenges and opportunities of such measures, we integrated "authenticated encryption with associated data" (AEAD) ciphers into the widely used SDS system Ceph, specifically, into its block storage interface, to secure the integrity of stored data and metadata. Ultimately, we identify the characteristics that an SDS system should possess to adopt our methodology.

Mohren, David [University of New Brunswick, Canada

A Privacy-Preserving Cyber Threat Intelligence Sharing System

Cyber Threat Intelligence (CTI) is a key resource for developing defensive strategies against potential cyber adversaries. Entities typically access CTI through open-source platforms, national agencies, or specialized commercial services. However, the bi-directional exchange of CTI is hindered by organizational trust boundaries, which complicate the sharing processes between entities and CTI providers. Centralized CTI services benefit from receiving suspicious cyber observables such as IP addresses, domain names, and email addresses from various entities. The aggregation allows for the correlation of widespread adversarial activities to enhance the alert and response mechanisms across the network of involved parties. Despite these benefits, openly sharing such observables incurs potential legal, regulatory, and reputational risks for the disclosing entities.This paper introduces a system designed to facilitate the secure exchange of cyber observables across trust boundaries without compromising the anonymity of the sharing entities. Here, we propose an architecture that leverages common web protocols alongside zero-knowledge proofs to authenticate members while maintaining anonymity. Additionally, we outline a privacy model tailored for STIX (Structured Threat Information eXpression) cyber observables to minimize the risk of inadvertently disclosing private information. Through our threat models, we assess the privacy implications of our proposed system and demonstrate its potential to enhance collaborative cyber defense efforts without exposing entities to undue risk.

BBS+ Signatures

The reactivity of experimentally reduced lunar regolith simulants: Health implications for future crewed missions to the lunar surface

Crewed missions to the Moon may resume as early as 2026 with NASA's Artemis III mission, and lunar dust exposure/inhalation is a potentially serious health hazard that requires detailed study. Current dust exposure limits are based on Apollo-era samples that spent decades in long-term storage on Earth; their diminished reactivity may lead to underestimation of potential harm that could be caused by lunar dust exposure. In particular, lunar dust contains nanophase metallic iron grains, produced by “space weathering”; the reactivity of this unique component of lunar dust is not well understood. Herein, we employ a chemical reduction technique that exposes lunar simulants to heat and hydrogen gas to produce metallic iron particles on grain surfaces. We assess the capacity of these reduced lunar simulants to generate hydroxyl radical (OH*) when immersed in deionized (DI) water, simulated lung fluid (SLF), and artificial lysosomal fluid (ALF). Lunar simulant reduction produces surface-adhered metallic iron “blebs” that resemble nanophase metallic iron particles found in lunar dust grains. Reduced samples generate ~5–100× greater concentrations of the oxidative OH* in DI water versus non-reduced simulants, which we attribute to metallic iron. SLF and ALF appear to reduce measured OH*. The increase in observed OH* generation for reduced simulants implies high oxidative damage upon exposure to lunar dust. Low levels of OH* measured in SLF and ALF imply potential damage to proteins or quenching of OH* generation, respectively. Reduction of lunar dust simulants provides a quick cost-effective approach to study dusty materials analogous to authentic lunar dust.

54 ENVIRONMENTAL SCIENCES

The LCLStream Ecosystem for Multi-Institutional Dataset Exploration

We describe a new end-to-end experimental data streaming framework designed from the ground up to support new types of applications – AI training, extremely high-rate X-ray time-of-flight analysis, crystal structure determination with distributed processing, and custom data science applications and visualizers yet to be created. Throughout, we use design choices merging cloud microservices with traditional HPC batch execution models for security and flexibility. This project makes a unique contribution to the DOE Integrated Research Infrastructure (IRI) landscape. By creating a flexible, API-driven data request service, we address a significant need for high-speed data streaming sources for the X-ray science data analysis community. With the combination of data request API, mutual authentication web security framework, job queue system, high-rate data buffer, and complementary nature to facility infrastructure, the LCLStreamer framework has prototyped and implemented several new paradigms critical for future generation experiments.

Rogers, David [ORNL] (ORCID:0000000251871768)

AQDrop Quantum Service (AQDrop) v1.0

AQDrop is a job management system designed to streamline access to the Advanced Quantum Testbed (AQT) at NERSC (National Energy Research Scientific Computing Center). It serves as a centralized middleware layer between researchers and quantum processing hardware. Key Features: AQDrop provides a FastAPI-based server backed by PostgreSQL for job submission, queue management, and role-based access control (members, operators, and administrators). Users submit Qiskit circuits via JSON payloads, which are queued, dispatched to the QPU through the Qubic API, and returned as measurement counts. A Python client library and web dashboard round out the interface options. Primary Use: Researchers submit quantum circuit jobs from a laptop or login node; an operator client executes those jobs on the AQT's physical QPU and returns results — all coordinated through the central API. Advantages: Compared to ad-hoc or direct hardware access, AQDrop adds structured queue management, auditable job-status tracking and OAuth2 authentication — reducing scheduling conflicts and unauthorized access. Its containerized deployment also improves reproducibility and scalability. Overall, AQDrop functions as a purpose-built quantum job broker tailored to NERSC's specific hardware and institutional access requirements.

Caplinger, Evan [Lawrence Berkeley National Labora

The New GlideinWMS Credentials Model and the New Challenges It Presents

The new credentials implementation of GlideinWMS and the recent migration from Grid Proxies to SciTokens presents new challenges in how we handle credentials and authenticate with grid resources. This presentation summarizes the features of the new model and explains the challenges we will have to address moving forward.

72 PHYSICS OF ELEMENTARY PARTICLES AND FIELDS

The Design and Evaluation of Zero Trust Architecture for Electric Vehicle Charging Infrastructure: EVs @ Scale Series on EV Charging Station Cybersecurity

Implementing a zero trust architecture can significantly bolster the security of electric vehicle (EV) charging infrastructure. EV charging infrastructure includes numerous networked interfaces, each of which can present potential vulnerabilities. When these vulnerabilities are exploited, they can compromise the entire system, leading to severe operational and security risks. Zero trust is a security model that operates on the principle of "never trust, always verify," which helps manage the attack surface and limit the scope of any potential compromises. Fundamentally, this model ensures that no entity, whether inside or outside the network, is trusted by default. The design principles of zero trust include continuous verification, strict deny-by-default access controls, and micro-segmentation. Continuous verification ensures that every request is thoroughly checked, regardless of its origin. Strict access controls enforce the principle of least privilege, allowing users and devices only the minimum necessary access to perform their functions. Micro-segmentation involves dividing the network into smaller, isolated segments to prevent lateral movement in case of a breach. In the context of EV charging infrastructure, zero trust can be implemented through various strategies. For example, multi-factor authentication (MFA) can be required for engineers to access the management interfaces and control systems of charging stations. Real-time monitoring and analysis of network traffic can help detect and respond to anomalies. Systems that do not need to communicate with each other can be micro-segmented to enhance security. All communications should adhere to predefined policies to be permitted. Additionally, encrypting communications can protect sensitive information exchanged between chargers and management systems. This paper presents a zero trust architecture specifically designed for EV charging infrastructure. Implementing zero trust not only mitigates risks but also builds a resilient infrastructure capable of withstanding and quickly recovering from cyber threats. The architecture addresses six defined security objectives. A comprehensive test plan is developed to assess the architecture against these objectives, and the results of the evaluation are reported. This approach is essential for maintaining the reliability and integrity of EV charging services in an increasingly interconnected and vulnerable digital landscape. This is the first in a planned series of papers exploring the implementation of zero trust in EV charging infrastructure. Each paper will delve into different aspects and applications of zero trust, highlighting how various work processes and requirements can lead to distinct architectural designs. These architectures will be tailored to address specific security challenges and operational needs within the EV charging ecosystem, ensuring a robust and adaptable security framework.

33 ADVANCED PROPULSION SYSTEMS

A Managed Tokens Service for Securely Keeping and Distributing Grid Tokens

Fermilab is transitioning authentication and authorization for grid operations to using bearer tokens based on the WLCG Common JWT (JSON Web Token) Profile. One of the functionalities that Fermilab experimenters rely on is the ability to automate batch job submission, which in turn depends on the ability to securely refresh and distribute the necessary credentials to experiment job submit points. Thus, with the transition to using tokens for grid operations, we needed to create a service that would obtain, refresh, and distribute tokens for experimenters’ use. This service would avoid the need for experimenters to be experts in obtaining their own tokens and would better protect the most sensitive long-lived credentials. Further, the service needed to be widely scalable, as we are currently keeping credentials active for approximately 15 experiments, each with 1-3 different credentials, and distributing those credentials to 2-20 submit points per experiment, with those numbers steadily increasing. To address these issues, we created and deployed a Managed Tokens service. The service is written in Go, taking advantage of that language’s native concurrency primitives to easily be able to scale operations as we onboard experiments. The service uses as its first credentials a set of kerberos keytabs, stored on the same secure machine that the Managed Tokens service runs on. These kerberos credentials allow the service to use htgettoken via condor_vault_storer to store vault tokens in the HTCondor credential managers (credds) that run on the batch system scheduler machines (HTCondor schedds); as well as downloading a local, shorter-lived copy of the vault token. The kerberos credentials are then also used to distribute copies of the locally-stored vault tokens to experiment submit points. When experimenters schedule jobs to be submitted, these distributed vault tokens are used to access a Hashicorp Vault instance (run separately from the Managed Tokens service), and previously-stored refresh tokens there are used to obtain the bearer token that is submitted with the job. We will discuss here the design of the Managed Tokens service, including elaborating on certain choices we made with regards to concurrent operations, configuration, monitoring, and deployment.

Bhat, Shreyas

Analyzing Risks of Virtual Private Network Connections

The use of Splunk for analyzing VPN logs is an effective approach for identifying vulnerabilities in network endpoints. Splunk, a powerful platform for searching, monitoring, and analyzing machine-generated data, enables organizations to aggregate VPN logs in real-time, providing insights into network activity, user behavior, and potential security risks. By indexing VPN traffic and authentication logs, security teams can track abnormal patterns such as multiple failed login attempts, unusual IP addresses, or unexpected changes in bandwidth usage, all of which could indicate potential vulnerabilities or breaches. With Splunk’s advanced search and reporting capabilities, users can create custom dashboards and alerts to detect suspicious activities. Automated searches can flag endpoints exhibiting unusual behavior, while correlation analysis can identify links between compromised devices and broader network vulnerabilities. In particular, Splunk's machine learning capabilities can be leveraged to predict and prevent threats by identifying trends that might otherwise be missed in traditional log analysis. This proactive approach to monitoring VPN logs allows for the early detection of security weaknesses, enabling rapid response and minimizing potential damage to network integrity. By enhancing endpoint visibility, Splunk plays a crucial role in securing remote connections and safeguarding sensitive information. Additionally, Splunk’s automation and alerting features allow teams to create custom workflows that notify them of vulnerable or misconfigured endpoints identified through Shodan. This synergy between Splunk’s log analysis and Shodan’s device intelligence enhances an organization’s ability to proactively identify and mitigate security risks, improving the overall resilience of their VPN infrastructure.

97 MATHEMATICS AND COMPUTING

A Taxonomy and Feature set for Server-Side Identification of Proxies

Malicious actors frequently use proxies and VPNs to evade detection and hide their origin. Current challenges to information security include the use of residential proxies to blend in with normal traffic and Man-in-the-Middle phishing proxies that are used to compromise accounts protected with mult-factor authentication. We advance a taxonomy and feature set for the identification of proxied traffic based on the network layer where proxying occurs. We describe how these features apply to common proxy types and how to use these features in the classification of the proxied traffic. Collection of these additional features is feasible using existing network sensors and web servers, while only adding about 30% volume to commonly deployed network sensor logs.

97 MATHEMATICS AND COMPUTING

Enabling Innovative Analysis on Heterogeneous Clusters through HTCdaskgateway

High energy particle (HEP) physics research is going through fundamental changes as we move to collect larger amounts of data from the Large Hadron Collider (LHC). Analysis facilities and distributed computing, through HTCs, have come together to create the next pythonic generation of analysis by utilizing HTCdaskgateway, a Dask gateway extension, allowing users to spawn workers compatible with both their analysis and heterogeneous clusters in line with authentication requirements. This is enabling physicists to engage with scientific python in ways they had not before because of domain specific C++ tools. An example of HTCdaskgateway’s use is Fermilab’s Elastic Analysis Facility.

Chavez, Elise [U. Wisconsin, Madison (main)]