Search NASA⌕ Search

SEARCH · Search NASA

Results for “cloud security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Leveraging the Cloud for Robust and Efficient Lunar Image Processing

The Lunar Mapping and Modeling Project (LMMP) is tasked to aggregate lunar data, from the Apollo era to the latest instruments on the LRO spacecraft, into a central repository accessible by scientists and the general public. A critical function of this task is to provide users with the best solution for browsing the vast amounts of imagery available. The image files LMMP manages range from a few gigabytes to hundreds of gigabytes in size with new data arriving every day. Despite this ever-increasing amount of data, LMMP must make the data readily available in a timely manner for users to view and analyze. This is accomplished by tiling large images into smaller images using Hadoop, a distributed computing software platform implementation of the MapReduce framework, running on a small cluster of machines locally. Additionally, the software is implemented to use Amazon's Elastic Compute Cloud (EC2) facility. We also developed a hybrid solution to serve images to users by leveraging cloud storage using Amazon's Simple Storage Service (S3) for public data while keeping private information on our own data servers. By using Cloud Computing, we improve upon our local solution by reducing the need to manage our own hardware and computing infrastructure, thereby reducing costs. Further, by using a hybrid of local and cloud storage, we are able to provide data to our users more efficiently and securely. 12 This paper examines the use of a distributed approach with Hadoop to tile images, an approach that provides significant improvements in image processing time, from hours to minutes. This paper describes the constraints imposed on the solution and the resulting techniques developed for the hybrid solution of a customized Hadoop infrastructure over local and cloud resources in managing this ever-growing data set. It examines the performance trade-offs of using the more plentiful resources of the cloud, such as those provided by S3, against the bandwidth limitations such use encounters with remote resources. As part of this discussion this paper will outline some of the technologies employed, the reasons for their selection, the resulting performance metrics and the direction the project is headed based upon the demonstrated capabilities thus far.

Cloud Computing↗

Bridging Cloud and Edge Computing at NREL Using CONNECT: Cloud Optimized Networking for Next-Gen Edge Computing Technologies [Slides]

CONNECT is an innovative on-premise hardware and software solution that integrates edge and cloud computing infrastructure at NREL. Built on the AWS Greengrass middleware and leveraging the MQTT protocol, CONNECT enables real-time data streaming from IoT devices and gateways to both cloud and local services, empowering researchers to rapidly capture, analyze, and act upon edge-generated data while leveraging cloud capabilities. The platform addresses research infrastructure challenges by providing a pre-approved platform which is already configured with the correct networking and cybersecurity baselines thus eliminating procurement delays and enabling on-demand availability. CONNECT's hybrid architecture efficiently manages burstable workloads, allowing research teams to dynamically scale computational capacity, handle peak data loads, and reduce operational bottlenecks. Advanced capabilities include built-in GPU support for executing machine learning models which enables low-latency inference at the edge from models trained in the cloud. This architecture supports real-time analytics and filtering, providing a mechanism to allow only transmitting and processing high-value data. Cloud-based configuration management permits engineers to manage on-premise systems remotely, optimizing operational efficiency. By bridging edge and cloud computing, CONNECT provides NREL researchers with a flexible, scalable platform that accelerates scientific discovery while maintaining robust security and performance standards.

97 MATHEMATICS AND COMPUTING↗

Zero Trust and Identity Access Management in Support of Service-Based Urban Air Mobility Applications

Urban Air Mobility environments will contain of a collection of service-based services, which will be typically hosted within cloud infrastructures. The underlying data for these UAM services will need to be secured. One approach to securing these UAM services would be to leverage the Zero Trust framework, that focuses on securing services and associated data, instead of securing the network. An early step in moving towards a Zero Trust framework is to standardize identity access manage support for an ever-widening set of services, where users must explicitly be granted access to each service.

UAM↗

Ensuring Flexibility and Security in SDN-Based Spacecraft Communication Networks Through Risk Assessment

Software-defined networking (SDN) has enabled elastic networking and resource distribution in cloud computing. The centralization and separation of the Control Plane also offers a high degree of network configurability and management, which can be used to mitigate and manage threats to the network. Space communication networks have historically been restricted and circuit switching in these networks has been a manual process. This study evaluates the potential role of SDN in space communication networks from a networking security standpoint. The evaluation covers the networking security needs of spacecraft missions and their associated assets. The results from the evaluation lead to a risk assessment that identifies vulnerabilities in an SDN-based communications architecture. Security challenges introduced into the network from integrating SDN are also considered. A risk register summarizes the severity of the attack outcomes, as well as occurrence likelihood. The study identifies Denial-of-Service (DoS) attacks as a new threat (presently unmitigated by existing security controls) that would be prevalent in an SDN-based space communication environment. A Mininet-based emulation testbed is built to demonstrate the susceptibility of spacecraft flight software to a flooding DoS attack when on an interconnected SDN-managed network. This type of attack would be highly consequential to mission assets, and therefore SDN-based space communications would need to be resilient to such attacks. Future work will need to be performed to fully characterize DoS attack methods that can apply to the space communication scenario, as well as to devise a comprehensive DoS-resilient solution.

Baker, Dylan Z.↗

Developing a Community of Practice for Applied Uses of Future PACE Data to Address Food Security Challenges

Ocean color satellite measurements have yielded valuable information about the base of the marine food web for over 20 years. The Plankton, Aerosol, Cloud, ocean Ecosystem (PACE) mission is building an advanced spectrometer to further refine ecosystem monitoring. Higher spectral resolution data from PACE will enable identification of additional marine biological indicators and their response to multiple stressors to guide sustainable management. Seafood is an important source of protein for a significant number of people. Wild catches cannot match increasing demand and their sustainability is in question. Aquaculture is an ever more important industry to feed the world's population. We share early efforts to engage a community of practice around food security to increase satellite data product use in support of resource management, business decisions, and policy analysis. Understanding the needs of applied scientists as well as non-traditional users of satellite data early in the PACE mission process will improve planning and preparation for a broader user base and hopefully help to mitigate food insecurity.

Schollaert Uz, Stephanie↗

eMosaic: Electrification Mosaic Platform for Grid Informed Smart Charging Management (Final Scientific/Technical Report)

ABB (Prime Contractor), in collaboration with its partners at the Utah State University (USU), Idaho National Laboratory, Rocky Mountain Power (RMP), and Electric Power Engineers (EPE), have performed research, development, and wide scale demonstration of a scalable and resilient Electrification Mosaic (eMosaic) platform for Smart Charge Management (SCM) for Electric Vehicle Infrastructure. Work was completed under DE EE0009194, titled “eMosaic Electrification Mosaic Platform for Grid Informed Smart Charging Management”, funded by the US Department of Energy. The project members developed algorithms that provide localized and bulk grid services and that reduce and stabilize costs all the way down the supply chain to the PEV owner through SCM. This platform aggregates telemetry from multiple data sources as pieces of the larger picture including personal, private fleet or transportation EVs, fast chargers and other supply equipment, weather service information, and geographically distributed charging sites such as public lots, garage and retail, and private or shared usage depots. ABB and the project team designed, tested, and improved a charging management system at local/edge and cloud levels. The ultimate objective of the project was to convincingly demonstrate that the developed secure eMosaic plat-form can be readily and favorably adopted by diverse utilities and site owners at scale. This was achieved through a demonstration plan with field deployment at several physical sites across 4 states and additional scalable simulation from high fidelity charging models.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Zero-Trust Architecture for Autonomous Edge Computing

We are at the apex of an aviation revolution where autonomy will play a central role in enabling complex, multi-agent systems to communicate, interact, and collaborate on a myriad of applications spanning autonomous swarms to wild-fire management. Autonomy is not an absolute but rather a spectrum ranging from a system requiring significant human intervention to one requiring little to none [1]. For example, the extreme, in the case of an autonomous aircraft, is one that operates independently in the airspace interacting with all other elements (air traffic controllers, other pilots) as if it were a human pilot. Critical to this vision is an architecture that enables autonomous agents to interact with minimal latency. Edge computing is an emerging architecture where compute and storage is pushed to the ‘edge’ of the network in order to minimize the round-trip time from agent to resource thereby mitigating the latency associated with cloud-only based approaches. Additionally, services can generate massive amounts of data (e.g., video feeds), which may require analysis in near real-time. Moving this data to the cloud for further processing may not be feasible due to latency, bandwidth, and cost. Privacy, security, and reliability can also be improved by edge computing architectures. However, this geo-distributed and dynamic* architecture complicates the establishment of unambiguous network security boundaries and can lead to vulnerabilities including man in the middle attacks, replay attacks, physical security breaches of edge nodes, signal interception, etc. This motivates the need for zero-trust architectures [2–4] which de-emphasize the notion of static network perimeters and, as the name implies, do not instill any innate trust in any particular agent. It is required that all agents must be authorized and approved in every transaction. In this paper, we present a zero-trust architecture suitable for edge-computing applications that demand significant low-latency, security, privacy, and reliability.

zero trust↗

Cloud Surprises in Moving NASA EOSDIS Applications into Amazon Web Services

NASA ESDIS has been moving a variety of data ingest, distribution, and science data processing applications into a cloud environment over the last 2 years. As expected, there have been a number of challenges in migrating primarily on-premises applications into a cloud-based environment, related to architecture and taking advantage of cloud-based services. What was not expected is a number of issues that were beyond purely technical application re-architectures. We ran into surprising network policy limitations, billing challenges in a government-based cost model, and difficulty in obtaining certificates in an NASA security-compliant manner. On the other hand, this approach has allowed us to move a number of applications from local hosting to the cloud in a matter of hours (yes, hours!!), and our CMR application now services 95% of granule searches and an astonishing 99% of all collection searches in under a second. And most surprising of all, well, you'll just have to wait and see the realization that caught our entire team off guard!

Cloud↗

Securing The Future: 2026 Manufacturing & Critical Infrastructure Threat Landscape

This report outlines the current state of manufacturing weaknesses introduced by the complexities of modern environments, including cloud services and Internet of Things (IoT) devices, with particular attention paid to the unique vulnerabilities encountered by SMMs. It also highlights CyManII’s strategic initiatives and collaborative solutions to mitigate these risks and strengthen the cybersecurity posture of the manufacturing ecosystem. Utilizing data from 2025 to inform forward-looking mitigation strategies, this report provides manufacturers with a clear understanding of both current and emerging cybersecurity threats, as well as practical opportunities to strengthen their cyber ecosystems. The following sections detail key vulnerabilities and threat vectors, along with actionable mitigation strategies, many of which have been developed or piloted through CyManII-led efforts. A thorough understanding of these risks and mitigation strategies is essential for manufacturers seeking to strengthen the security and resilience of their manufacturing operations.

3D Printing↗

Redefining Tactical Operations for MER Using Cloud Computing

The Mars Exploration Rover Mission (MER) includes the twin rovers, Spirit and Opportunity, which have been performing geological research and surface exploration since early 2004. The rovers' durability well beyond their original prime mission (90 sols or Martian days) has allowed them to be a valuable platform for scientific research for well over 2000 sols, but as a by-product it has produced new challenges in providing efficient and cost-effective tactical operational planning. An early stage process adaptation was the move to distributed operations as mission scientists returned to their places of work in the summer of 2004, but they would still came together via teleconference and connected software to plan rover activities a few times a week. This distributed model has worked well since, but it requires the purchase, operation, and maintenance of a dedicated infrastructure at the Jet Propulsion Laboratory. This server infrastructure is costly to operate and the periodic nature of its usage (typically heavy usage for 8 hours every 2 days) has made moving to a cloud based tactical infrastructure an extremely tempting proposition. In this paper we will review both past and current implementations of the tactical planning application focusing on remote plan saving and discuss the unique challenges present with long-latency, distributed operations. We then detail the motivations behind our move to cloud based computing services and as well as our system design and implementation. We will discuss security and reliability concerns and how they were addressed

Mars↗

An Integrated Data Analytics Platform

An Integrated Science Data Analytics Platform is an environment that enables the confluence of resources for scientific investigation. It harmonizes data, tools and computational resources which subsequently enable the research community to focus on the investigation rather than spending time on security, data preparation, management, etc. OceanWorks is a NASA technology integration project to establish a cloud-based Integrated Ocean Science Data Analytics Platform at NASA’s Physical Oceanography Distributed Active Archive Center (PO.DAAC) for big ocean science. It focuses on advancement and maturity by bringing together several NASA open-source, big data projects for parallel analytics, anomaly detection, in-situ to satellite data matchup, quality-screened data subsetting, search relevancy, and data discovery. Our communities are relying on data distributed through data centers such as the PO.DAAC, COAPS, NCAR, and many others to conduct their research. In typical investigations, scientists would engage in: search for data, evaluate the relevance of that data, download it, and then apply algorithms to identify trends. Such workflow cannot scale if the research involves a massive amount of data or multi-variate measurements. NASA’s Surface Water and Ocean Topography (SWOT) mission is expected to produce massive amount of observational data during its 3-year nominal mission. Collections like SWOT challenges all existing Earth Science data archival, distribution and analysis paradigms. In this paper, we will discuss how OceanWorks enhances the analysis of physical ocean data where the computation is done on an elastic cloud platform next to the archive to deliver fast, web-accessible services for working with oceanographic measurements.

Yang, Chaowei↗

Zero Trust Strategies for Chemical, Biological, Radiological, and Nuclear Detection Systems: D.1 Cyber Scenarios

The evolving landscape of cybersecurity necessitates a paradigm shift to a Zero Trust (ZT) model, which assumes breaches and continuously verifies trust. This approach reshapes how trust boundaries are established, focusing on identities, devices, networks, applications, and data, rather than solely relying on perimeter defenses such as firewalls. Central to this transformation is the National Institute of Standards and Technology's (NIST) Special Publication 800-207, outlining the Zero Trust Architecture (ZTA), along with Executive Order 14028, which mandates federal agencies to adopt ZT principles. Complementary to these efforts, the Cybersecurity and Infrastructure Security Agency (CISA) developed the Zero Trust Maturity Model (ZTMM), providing a framework with five pillars and three cross-cutting capabilities to guide agencies toward enhanced cybersecurity maturity. In support of these initiatives, the DHS Countering Weapons of Mass Destruction Office (CWMD) is applying ZT principles to secure Chemical, Biological, Radiological, and Nuclear (CBRN) detection systems. Recognizing the diverse deployment models and network connectivity of these systems—from stationary, non-networked units to mobile, cloud-connected devices—the Pacific Northwest National Laboratory (PNNL) is developing cybersecurity scenarios specifically for CBRN environments. These scenarios examine various configurations and technological capabilities, offering insights into the application of ZTMM pillars in enhancing the security postures of CBRN devices. The cybersecurity scenarios presented by PNNL are hypothetical, crafted to explore theoretical situations and stimulate discussion on the potential use or compromise of CBRN detection systems in varied contexts. These narratives are illustrative and do not reference any real events or actual networks. Instead, they employ generalized reference models to highlight concepts and potential issues within CBRN security, focusing on how Zero Trust strategies can be adapted to address these challenges effectively.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Aviation Applications for Satellite-Based Observations of Cloud Properties, Convection Initiation, In-flight Icing, Turbulence and Volcanic Ash

Advanced Satellite Aviation Weather Products (ASAP) was jointly initiated by the NASA Applied Sciences Program and the NASA Aviation Safety and Security Program in 2002. The initiative provides a valuable bridge for transitioning new and existing satellite information and products into Federal Aviation Administration (FAA) Aviation Weather Research Program (AWRP) efforts to increase the safety and efficiency of the airspace system. The ASAP project addresses hazards such as convective weather, turbulence (clear-air and cloud-induced), icing and volcanic ash and is particularly applicable in extending the monitoring of weather over data-sparse areas such as the oceans and other observationally remote locations. ASAP research is conducted by scientists from NASA, the FAA AWRP's Product Development Teams (PDT), NOAA and the academic research community. In this paper we provide a summary of activities since the inception of ASAP that emphasize the use of current-generation satellite technologies toward observing and mitigating specified aviation hazards. A brief overview of future ASAP goals is also provided in light of the next generation of satellite sensors (e.g., hyperspectral; high spatial resolution) to become operational in the 2006-2013 timeframe.

Mecikalski, John R.↗

A Review of Edge Computing Technology and Its Applications in Power Systems

Recent advancements in network-connected devices have led to a rapid increase in the deployment of smart devices and enhanced grid connectivity, resulting in a surge in data generation and expanded deployment to the edge of systems. Classic cloud computing infrastructures are increasingly challenged by the demands for large bandwidth, low latency, fast response speed, and strong security. Therefore, edge computing has emerged as a critical technology to address these challenges, gaining widespread adoption across various sectors. This paper introduces the advent and capabilities of edge computing, reviews its state-of-the-art architectural advancements, and explores its communication techniques. A comprehensive analysis of edge computing technologies is also presented. Furthermore, this paper highlights the transformative role of edge computing in various areas, particularly emphasizing its role in power systems. It summarizes edge computing applications in power systems that are oriented from the architectures, such as power system monitoring, smart meter management, data collection and analysis, resource management, etc. Additionally, the paper discusses the future opportunities of edge computing in enhancing power system applications.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Leveraging ARM Data to Improve Models for Predictive Understanding of Energy and Security Challenges

Extreme weather and natural hazards can disrupt the energy sector, affecting demand, generation, transmission, distribution, consumption and operational planning at regional and national scales. These disruptions stem from a broad range of atmospheric phenomena, including winter storms, freezing rain, wet snow loading, severe convection, flooding and landslides, wildfires, prolonged heat, and drought. Many of these same phenomena can also affect national security through impacts to transportation and infrastructure. To support the U.S. Department of Energy (DOE) focus on energy resilience and national security, the Atmospheric Radiation Measurement (ARM) User Facility is uniquely positioned to contribute measurement data, analyses, and modeling frameworks that can significantly improve predictive understanding of these hazards to mitigate their effects. To explore this opportunity, ARM convened a two-part virtual workshop in November 2025. The workshop engaged interdisciplinary experts in atmospheric science, energy systems, modeling, and operations. The goal of the meeting was to engage with these interdisciplinary experts to address three questions: • What are examples of atmospheric processes that represent significant risks to energy security or national security and where are those risks greatest? • What measurements or measurement strategies would improve ARM’s capacity to address these issues? • How can ARM and users of the ARM facility better work with the Energy Exascale Earth System Model (E3SM) and multi-sector modeling communities to apply ARM data to improving E3SM simulations of these phenomena? Participants were asked to submit white papers ahead of the meeting to initiate thinking on these themes and to help organize discussions. Workshop sessions were then organized around themes identified in the white papers. First from the white papers and then through subsequent discussions, workshop participants identified many examples that address the three questions listed above. Participants called out energy system vulnerabilities to weather phenomena such as the impact of freezing rain, strong winds, and excessive heat on power grids. They also noted the effects that weather phenomena could have on energy demand or supply (e.g., through effects of extreme temperatures). They called out security vulnerabilities such as impacts to crops from aerosol-borne pathogens and risks to industry due to melting permafrost in the Arctic. In all, over a dozen meteorological phenomena were linked to energy or security vulnerabilities. For many of the identified phenomena, participants pointed out where ARM was well poised to address issues (e.g., through measurements of cloud microphysics to inform studies of freezing rain) but also noted needs for additional measurements or modified measurement strategies. For example, adaptive scanning of severe weather would be valuable for probing winter storms or severe convection. Participants pointed out the value in integrating external observations with ARM measurements and with applying artificial intelligence (AI) to ARM observation analysis and they advocated for using model simulations to help optimize measurement strategies through Observing System Simulation Experiments (OSSEs). It was clear from the workshop that there are many ways that ARM observations can be used to mitigate energy and security concerns, but meeting participants were also asked to identify what they considered to be the greatest opportunities by ranking issues pertaining to the three workshop questions. This was accomplished through a survey administered to participants between the two virtual sessions. The highest-priority phenomena identified were winter storms, severe convection, and arctic processes. Discussion in the second session, therefore, focused primarily on these three areas, which were most fully developed in exploring ARM opportunities. Nevertheless, it was also clear that ARM has opportunities to contribute to all the identified topics. This report describes the workshop, including input from discussion and white papers (Sections 2 and 3) and a list of priority recommendations (section 4). Many other ideas for ARM contributions are discussed in individual white papers (Appendix D).

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

An Offload NIC for NASA, NLR, and Grid Computing

This work addresses distributed data management and access dynamically configurable high-speed access to data distributed and shared over wide-area high-speed network environments. An offload engine NIC (network interface card) is proposed that scales at nX10-Gbps increments through 100-Gbps full duplex. The Globus de facto standard was used in projects requiring secure, robust, high-speed bulk data transport. Novel extension mechanisms were derived that will combine these technologies for use by GridFTP, bandwidth management resources, and host CPU (central processing unit) acceleration. The result will be wire-rate encrypted Globus grid data transactions through offload for splintering, encryption, and compression. As the need for greater network bandwidth increases, there is an inherent need for faster CPUs. The best way to accelerate CPUs is through a network acceleration engine. Grid computing data transfers for the Globus tool set did not have wire-rate encryption or compression. Existing technology cannot keep pace with the greater bandwidths of backplane and network connections. Present offload engines with ports to Ethernet are 32 to 40 Gbps f-d at best. The best of ultra-high-speed offload engines use expensive ASICs (application specific integrated circuits) or NPUs (network processing units). The present state of the art also includes bonding and the use of multiple NICs that are also in the planning stages for future portability to ASICs and software to accommodate data rates at 100 Gbps. The remaining industry solutions are for carrier-grade equipment manufacturers, with costly line cards having multiples of 10-Gbps ports, or 100-Gbps ports such as CFP modules that interface to costly ASICs and related circuitry. All of the existing solutions vary in configuration based on requirements of the host, motherboard, or carriergrade equipment. The purpose of the innovation is to eliminate data bottlenecks within cluster, grid, and cloud computing systems, and to add several more capabilities while reducing space consumption and cost. Provisions were designed for interoperability with systems used in the NASA HEC (High-End Computing) program. The new acceleration engine consists of state-ofthe- art FPGA (field-programmable gate array) core IP, C, and Verilog code; novel communication protocol; and extensions to the Globus structure. The engine provides the functions of network acceleration, encryption, compression, packet-ordering, and security added to Globus grid or for cloud data transfer. This system is scalable in nX10-Gbps increments through 100-Gbps f-d. It can be interfaced to industry-standard system-side or network-side devices or core IP in increments of 10 GigE, scaling to provide IEEE 40/100 GigE compliance.

Awrach, James↗

Prognostics As-A-Service (PaaS)

Deep awareness of aircraft system health-state is critical for maintaining safe, efficient growth in global operations and enabling autonomy. Maintainers, operators, controllers, dispatchers, pilots, and autonomous systems must have reliable real-time predictions of vehicle health to preserve safety and efficiency. We will explore the feasibility and challenges of cloud enhanced prognostics. Aircraft request PaaS in flight to supplement onboard systems or provide complete health awareness. We will explore and demonstrate the ability to address six major challenges of PaaS: Generality, Environmental Complexity, Utility, Trust, Communications, and Security. We will also explore the factors in the decision to host prognostics onboard vs As-A-Service.

Prognostics As A Service↗

Tensile properties of impact ices

A special test apparatus was developed to measure the tensile strength of impact ices perpendicular to the direction of growth. The apparatus consists of a split tube carefully machined to minimize the effect of the joint on impact ice strength. The tube is supported in the wind tunnel by two carefully aligned bearings. During accretion the tube is turned slowly in the icing cloud to form a uniform coating of ice on the split tube specimen. The two halves of the split tube are secured firmly by a longitudinal bolt to prevent relative motion between the two halves during ice accretion and handling. Tensile test strength results for a variety of icing conditions were obtained. Both glaze and rime ice conditions were investigated. In general, the tensile strength of impact ice was significantly less than refrigerator ice. Based on the limited data taken, the median strength of rime ice was less than glaze ice. However, the mean values were similar.

Chu, M. L.↗