Search NASASearch

SEARCH · Search NASA

Results for “web services”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

45 records · Page 3

A Privacy-Preserving Cyber Threat Intelligence Sharing System

Cyber Threat Intelligence (CTI) is a key resource for developing defensive strategies against potential cyber adversaries. Entities typically access CTI through open-source platforms, national agencies, or specialized commercial services. However, the bi-directional exchange of CTI is hindered by organizational trust boundaries, which complicate the sharing processes between entities and CTI providers. Centralized CTI services benefit from receiving suspicious cyber observables such as IP addresses, domain names, and email addresses from various entities. The aggregation allows for the correlation of widespread adversarial activities to enhance the alert and response mechanisms across the network of involved parties. Despite these benefits, openly sharing such observables incurs potential legal, regulatory, and reputational risks for the disclosing entities.This paper introduces a system designed to facilitate the secure exchange of cyber observables across trust boundaries without compromising the anonymity of the sharing entities. Here, we propose an architecture that leverages common web protocols alongside zero-knowledge proofs to authenticate members while maintaining anonymity. Additionally, we outline a privacy model tailored for STIX (Structured Threat Information eXpression) cyber observables to minimize the risk of inadvertently disclosing private information. Through our threat models, we assess the privacy implications of our proposed system and demonstrate its potential to enhance collaborative cyber defense efforts without exposing entities to undue risk.

BBS+ Signatures

PNNL Review of Federal and State Agency Regulatory Streamlining Practices

All major federal actions that have the potential to significantly affect the environment (e.g., land purchases and/or issuing grants, permits, leases, or licenses) are subject to multiple statutes including the following: • an environmental analysis under the National Environmental Policy Act (NEPA) • potential consultations with the U.S. Fish and Wildlife Service (USFWS) and/or National Marine Fisheries Service (NMFS) under the Endangered Species Act of 1973, as amended (ESA) • potential consultations with State Historical Preservation Officers (SHPOs) and/or tribal nations [often Tribal Historic Preservation Officers (THPOs)] under the National Historic Preservation Act of 1966 (NHPA). Given the size of the federal government and the corresponding variability and complexity in its missions, different branches within the federal government have a fairly wide range of approaches to fulfill their NEPA and consultation requitements. Many of these approaches are founded on the desire to streamline their NEPA and consultation processes while meeting the spirit and letter of the regulations. Some federal and state environmental/engineering agencies have developed web-based dashboards that provide a single web location for permit application submittals. They also use general permits in their various permitting processes. General permits can streamline the permitting process by establishing identical requirements for all eligible applicants. This reduces the time these agencies need to spend reviewing individual permits and setting specific requirements. In addition, general permits do not require a case-specific permit application. This paper presents a sampling of effective agency examples of streamlining the NEPA process and associated agency consultations. It also includes several examples of federal and state agency web portals, online application systems, and general permits that make application processes more efficient and accessible.

54 ENVIRONMENTAL SCIENCES

Fermilab s Transition to Token Authentication

Fermilab is the first High Energy Physics institution to transition from X.509 user certificates to authentication tokens in production systems. All of the experiments that Fermilab hosts are now using JSON Web Token (JWT) access tokens in their grid jobs. Many software components have been either updated or created for this transition, and most of the software is available to others as open source. The tokens are defined using the WLCG Common JWT Profile. Token attributes for all the tokens are stored in the Fermilab FERRY system which generates the configuration for the CILogon token issuer. High security-value refresh tokens are stored in Hashicorp Vault configured by htvault-config, and JWT access tokens are requested by the htgettoken client through its integration with HTCondor. The Fermilab job submission system jobsub was redesigned to be a lightweight wrapper around HTCondor. For automated job submissions a managed tokens service was created to reduce duplication of effort and knowledge of how to securely keep tokens active. The existing Fermilab file transfer tool ifdh was updated to work seamlessly with tokens, as well as the Fermilab POMS (Production Operations Management System) which is used to manage automatic job submission and the RCDS (Rapid Code Distribution System) which is used to distribute analysis code via the CernVM FileSystem. The dCache storage system was reconfigured to accept tokens for authentication in place of X.509 proxy certificates. As some services and sites have not yet implemented token support, proxy certificates are still sent with jobs for backwards compatibility but some experiments are beginning to transition to stop using them. There have been some glitches and learning curve issues but in general the system has been performing well and is being improved as operational problems are addressed.

Dykstra, David

Fermilab's Transition to Token Authentication

Fermilab is the first High Energy Physics institution to transition from X.509 user certificates to authentication tokens in production systems. All the experiments that Fermilab hosts are now using JSON Web Token (JWT) access tokens in their grid jobs. Many software components have been either updated or created for this transition, and most of the software is available to others as open source. The tokens are defined using the WLCG Common JWT Profile. Token attributes for all the tokens are stored in the Fermilab FERRY system which generates the configuration for the CILogon token issuer. High security-value refresh tokens are stored in Hashicorp Vault configured by htvault-config, and JWT access tokens are requested by the htgettoken client through its integration with HTCondor. The Fermilab job submission system jobsub was redesigned to be a lightweight wrapper around HTCondor. The grid workload management system GlideinWMS which is also based on HTCondor was updated to use tokens for pilot job submission. For automated job submissions a managed tokens service was created to reduce duplication of effort and knowledge of how to securely keep tokens active. The existing Fermilab file transfer tool ifdh was updated to work seamlessly with tokens, as well as the Fermilab POMS (Production Operations Management System) which is used to manage automatic job submission and the RCDS (Rapid Code Distribution System) which is used to distribute analysis code via the CernVM FileSystem. The dCache storage system was reconfigured to accept tokens for authentication in place of X.509 proxy certificates. As some services and sites have not yet implemented token support, proxy certificates are still sent with jobs for backwards compatibility, but some experiments are beginning to transition to stop using them.

Dykstra, Dave [Fermilab] (ORCID:0000000326539015)

EVI-LOCATE User Manual

One of the longest stages in the deployment of electric vehicle supply equipment (EVSE) is the initial planning of the infrastructure itself. Engineers and fleet experts from the National Renewable Energy Laboratory (NREL) have supported dozens of charging infrastructure site plans over the past couple decades, including the generation of site schematics, determinations of electric capacity, and estimates for likely costs. As the market for electric vehicles (EVs) has matured, this approach should no longer require a time and personnel intensive process. In order to shorten the time taken to develop site plans and cost estimates, NREL developed a tool that fleet managers, facility managers, electricians, EVSE installers, and members of the public can use to develop initial schematics and ballpark pricing for charging station installations. The Electric Vehicle Infrastructure - Locally Optimized Charger Assessment Tool and Estimator (EVI-LOCATE) provides a structured and consistent way for users to enter information about their planned EVSE project in a relatively simple web-based format. EVI-LOCATE then calculates electrical equipment capacity, wiring runs, and project costs. It produces a site diagram optimized around surface characteristics with differential trenching costs for softscape such as grass compared to hardscape such as asphalt that can be adjusted by users in the tool. It also stores the resulting site plans and costs in a dashboard for access at a later date, including plan revisions if necessary. This document guides users through the EVI-LOCATE screens and associated questions. It contains tip text boxes throughout on how best to interface with the tool and find additional information or context. The appendices contain the assumptions and calculations underpinning the tool. Much of the information for EVI-LOCATE was gathered through industry engagements with EVSE installers, invoices from completed EVSE installations, Gordian's RS Means construction data, and the General Services Administration blanket purchase agreement for EVSE. For a visual tutorial of the tool, users can watch EVI-LOCATE Step-by-Step Video. The tool itself is available at https://evi-locate.nrel.gov.

29 ENERGY PLANNING, POLICY, AND ECONOMY

NFPA Distributed Energy Resources Safety Training (DERST) For Emergency Responders

The National Fire Protection Association, with support from the Department of Energy, executed a multi-year initiative to develop, enhance, and disseminate Distributed Energy Resources Safety Training (DERST) tools for U.S. emergency responders. As Distributed Energy Resources (DER)—such as solar photovoltaics, battery energy storage systems (ESS), electric vehicles (EVs), and associated infrastructure—become increasingly prevalent, the NFPA identified a critical need for up-to-date standardized, accessible, and effective safety training tailored for the fire service and related public safety professionals. The project delivered a comprehensive suite of educational resources to improve responders’ abilities to safely manage DER-related incidents. This included: • Revised Modular Training Courses: Updated classroom-based DER safety courses, now modular and accessible nationwide through fire academies and the North American Fire Training Directors (NAFTD) network. • Live Burn Testing & Research: A full-scale controlled burn of a DER-equipped residential structure provided real-world data and insights, forming the basis for updated best practices. • A Gamified Simulation Tool – Firefighters Incident Response Simulation Tool (FIRST): A first-of-its-kind, multiplayer, scenario-based simulation using the Unreal Engine 5.0 to train responders in a realistic virtual, multi-DER incident environment. • Field Familiarization Software Tools & Prop Guide: Digital DER field familiarization evolutions software guide and a prop development manual to support field-based DER training exercises, enhancing responders' hands-on familiarity with DER infrastructure and collaboration on virtual incident responses. • National Dissemination Strategy: Strategic partnerships with NAFTD, Vector Solutions, and others enabled wide-scale distribution, with over 5,000 departments accessing resources and 1,100+ departments adopting the simulator in the first seven months. Also provided a web portal for easy access to all training and simulation programs developed under this grant for the U.S. responder community. Key findings from the project—particularly from the burn test—led to paradigm shifts in fire response tactics. For example, traditional approaches to garage fires may be hazardous if DERs are present, due to explosive off gassing and thermal runaway risks. The new training emphasizes scene assessment, stand-off approaches, thermal imaging verification, and careful post-incident cooling of DER components to prevent reignition. This initiative has had a significant national impact, raising awareness, enhancing preparedness, and supporting safer DER incident response practices. Significant engagement from the media, public safety organizations, and PBS coverage has further amplified the reach and adoption of NFPA’s DER safety training, tools, and simulations.

14 SOLAR ENERGY

Food web dynamics drive variation in Smallmouth Bass Micropterus dolomieu mercury contamination in protected Southern Appalachian streams

Mercury is a global pollutant that threatens otherwise protected aquatic ecosystems. Mercury food web dynamics are not well understood in streams with no point sources of contamination but have the potential to concentrate this dangerous pollutant in upper trophic level consumers. A 2016 study revealed that mercury concentrations of Smallmouth Bass Micropterus dolomieu varied between three streams in Great Smoky Mountains National Park (GSMNP), Tennessee, USA. We tested the hypothesis that food web interactions drive spatial variation in mercury concentrations of the apex predator of protected stream ecosystems. We measured carbon and nitrogen stable isotope ratios, and mercury concentrations of eight food web components of GSMNP streams including basal resources, intermediate consumers, and Smallmouth Bass, the apex predator. Mean THg concentrations of basal resources did not differ between streams, but the spatial pattern of concentrations of intermediate consumers mirrored Smallmouth Bass. Relationships between organismal contaminant concentrations and trophic level were positive in all three streams, indicating biomagnification is occurring in the protected streams of GSMNP. Furthermore, our findings indicate that mercury dynamics in intermediate trophic levels, rather than differences in basal resource concentrations, may drive differences in mercury contamination of apex predators of the protected stream ecosystems of GSMNP.

Bioaccumulation

Subsurface Energy Systems Mapping Inquiry Tool (MapIT)

The Subsurface Energy Systems Mapping Inquiry Tool (MapIT) is an online web mapping tool designed to help users discover available public-sourced data to facilitate data exploration for subsurface energy exploration and characterization efforts for resource identification (e.g. critical minerals, hydrocarbons, geothermal) as well as injection of geologic sequestration of carbon dioxide (e.g. enhanced oil recovery, saline storage, etc.). Modules within the tool curate data related to geology, faults, fractures, injection and confining zones, hydrologic information, groundwater, groundwater wells, geomechanical and petrophysical data, and geochemical data. User documentation on how to use the tool is also provided. Data have been collected from authoritative national, state, and local sources and made available in this tool. The data is also available as a data catalog and Esri Geodatabase at: https://edx.netl.doe.gov/dataset/mapit-database Disclaimer: There is no guarantee of completeness or appropriateness for individual user’s requirements. Use of this tool is solely at the discretion of the user. See full Federal Disclaimer for further information (https://netl.doe.gov/home/disclaimer). This project was funded by the United States Department of Energy, National Energy Technology Laboratory, in part, through a site support contract. Neither the United States Government nor any agency thereof, nor any of their employees, nor the support contractor, nor any of their employees, makes any warranty, express or implied, or assumes any legal liability or responsibility for the accuracy, completeness, or usefulness of any information, apparatus, product, or process disclosed, or represents that its use would not infringe privately owned rights. Reference herein to any specific commercial product, process, or service by trade name, trademark, manufacturer, or otherwise does not necessarily constitute or imply its endorsement, recommendation, or favoring by the United States Government or any agency thereof. The views and opinions of authors expressed herein do not necessarily state or reflect those of the United States Government or any agency thereof. https://www.netl.doe.gov/home/disclaimer

Carbon Sequestration

Expanding Access to Science Participation: A FAIR Framework for Petascale Data Visualization and Analytics

The massive data generated by scientists daily serve as both a major catalyst for new discoveries and innovations, as well as a significant roadblock that restricts access to the data. Here, our paper introduces a new approach to removing Big Data barriers and democratizing access to petascale data for the broader scientific community. Our novel data fabric abstraction layer allows user-friendly querying of scientific information while hiding the complexities of dealing with file systems or cloud services. We enable FAIR (Findable, Accessible, Interoperable, and Reusable) access to datasets such as NASA’s petascale climate datasets. Our paper presents an approach to managing, visualizing, and analyzing petabytes of data within a browser on equipment ranging from the top NASA supercomputer to commodity hardware like a laptop. Our novel data fabric abstraction utilizes state-of-the art progressive compression algorithms and machine-learning insights to power scalable visualization dashboards for petascale data. The result provides users with the ability to identify extreme events or trends dynamically, expanding access to scientific data and further enabling discoveries. We validate our approach by improving the ability of climate scientists to visually explore their data via three fully interactive dashboards. We further validate our approach by deploying the dashboards and simplified training materials in the classroom at a minority-serving institution. These dashboards, released in simplified form to the general public, contribute significantly to a broader push to democratize the access and use of climate data.

Computer science