Search NASASearch

SEARCH · Search NASA

Results for “access control”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

The D3 Middleware Architecture

DARWIN is a NASA developed, Internet-based system for enabling aerospace researchers to securely and remotely access and collaborate on the analysis of aerospace vehicle design data, primarily the results of wind-tunnel testing and numeric (e.g., computational fluid-dynamics) model executions. DARWIN captures, stores and indexes data; manages derived knowledge (such as visualizations across multiple datasets); and provides an environment for designers to collaborate in the analysis of test results. DARWIN is an interesting application because it supports high-volumes of data. integrates multiple modalities of data display (e.g., images and data visualizations), and provides non-trivial access control mechanisms. DARWIN enables collaboration by allowing not only sharing visualizations of data, but also commentary about and views of data. Here we provide an overview of the architecture of D3, the third generation of DARWIN. Earlier versions of DARWIN were characterized by browser-based interfaces and a hodge-podge of server technologies: CGI scripts, applets, PERL, and so forth. But browsers proved difficult to control, and a proliferation of computational mechanisms proved inefficient and difficult to maintain. D3 substitutes a pure-Java approach for that medley: A Java client communicates (though RMI over HTTPS) with a Java-based application server. Code on the server accesses information from JDBC databases, distributed LDAP security services, and a collaborative information system. D3 is a three tier-architecture, but unlike 'E-commerce' applications, the data usage pattern suggests different strategies than traditional Enterprise Java Beans - we need to move volumes of related data together, considerable processing happens on the client, and the 'business logic' on the server-side is primarily data integration and collaboration. With D3, we are extending DARWIN to handle other data domains and to be a distributed system, where a single login allows a user transparent access to test results from multiple servers and authority domains.

Walton, Joan

Design of a remote-controlled mount for IOTA’s magnet undulator

The SLAC undulator is essential for studies of synchrotron radiation produced by a single electron in IOTA. Since IOTA is meant for different experiments, the undulator is not always needed, so it must be pushed and pulled back depending upon the nature of the experiment. Moving the undulator manually result in significant time loss about 30 minutes for the controlled access, and about 30 minutes to achieve beam injector in IOTA. Because the operation is done manually is not easy to ensure a good repeatability of the undulator position. That’s why IOTA’s team decided to set-up a completely remote-controlled mount.

42 ENGINEERING

NGSLR Safety Handbook

NASA's Next Generation Satellite Laser Ranging (NGSLR) station is the prototype for NASA's Satellite Laser Ranging (SLR) systems which will be deployed around the world in the coming decade. The NGSLR system will be an autonomous, photon-counting SLR station with an expected absolute range accuracy of better than one centimeter and a normal point (time-averaged) range precision better than one millimeter. The system provides continuous (weather permitting), 24 hour tracking coverage to an existing constellation of approximately two dozen artificial satellites equipped with passive retroreflector arrays, using pulsed, 532 nm, class IV laser systems. Current details on the approved laser systems can be found in the Appendix 1 of this document. This safety plan addresses the potential hazards to emitted laser radiation, which can occur both inside and outside the shelter. Hazards within the shelter are mitigated through posted warning signs, activated warning lights, procedural controls, personal protective equipment (PPE), laser curtains, beam blocking systems, interlock controls, pre-configured laser control settings, and other controls discussed in this document. Since the NGSLR is a satellite tracking system, laser hazards exist outside the shelter to personnel on the shelter roof and to passing aircraft. Potential exposure to personnel outside the system is mitigated through the use of posted warning signs, access control, procedural controls, a stairwell interlock, beam attenuation/blocking devices, and a radar based aircraft detection system.

satellite laser ranging

Precedency control and other semantic integrity issues in a workbench database

Most database systems model the current state of a system of real world discrete and simple entities together with their relationships. By examining instead a database system that is a workbench and models more complicated entities, a fresh perspective is gained. Specifically, semantic integrity is analysed. Four aspects distinct from physical integrity are identified, namely - access, failure, concurrency and precedency. Access control is shown to be the consequence of semantic interdependency between data and its matching semantic routines. Failure, concurrency precedency controls are concerned with preventing processes interfering with each other. Precedency is a new concept in the database context. It expresses a constraint between processes that act on the database. As processes create, update and delete entities they in general obey a partial ordering imposed by the semantics of their actions. Precedency control ensures that data remains consistent with respect to this partial order.

Dampney, C. N. G.

Architecture of the personnel protection systems for Spallation Neutron Source Second Target Station

The Oak Ridge National Laboratory (ORNL) is implementing a major upgrade to the Spallation Neutron Source (SNS) facility, encompassing the addition of the Second Target Station (STS). Preliminary design reviews have been conducted on several STS Personnel Protection Systems (PPS). The reviews focused primarily on the integration with the existing SNS PPS, the new proton transport tunnel, and the target areas. Development of the PPS is ongoing, to ensure a coherent safety system with the mission of protecting users and workers from prompt radiation hazards while providing high beam availability to operations. The STS PPS element in the Integrated Control System (ICS) is a facility-wide system composed of multiple safety subsystems, including the Ring to Second Target (RTST) beam transport tunnel, Target, Bunker and Instruments. Personnel working in all these geographic areas are protected by modular reliable PPS solutions. The safety system enforces access controls, radiation monitoring, beam destination control, and application of critical device inhibit upon detection of abnormal condition. It uses well-documented processes, Common Industrial Protocol (CIP) safety, pulsed test, and redundancy to achieve the desired Safety Integrity Level (SIL). This paper gives an architectural overview of the STS PPS and a detailed safety plan for the SNS facility, addressing safety solutions and human factors.

Michaelides, Tommy [ORNL] (ORCID:0000000190499869)

Scan‐Path‐ and Initial‐State‐Dependent Superdomain Switching in (111)‐Oriented PZT

Polarization switching in ferroelectric materials arises from the collective evolution of complex domain hierarchies, yet deterministic control over these processes remains challenging. Here, we investigate scan-path- and initial-state-dependent switching in epitaxial (111)-oriented PbZr 0.2 Ti 0.8 O 3 thin films using automated AFM-based writing combined with quantitative 3D piezoresponse force microscopy. We show that the scan trajectory acts as an experimentally accessible control parameter for superdomain formation. Box-in-box raster scans reproducibly stabilize ordered stripe superdomains with a reduced subset of symmetry-allowed variants, whereas spiral trajectories generate frustrated mixed-variant states with a broader distribution of final microstructures. Automated pulsing experiments further show that the local superdomain configuration at the nucleation site strongly influences the final written morphology. Phase-field modeling qualitatively reproduces the contrast between representative initial-state geometries and supports the role of compatibility constraints among competing ferroelastic pathways. These findings establish scan-path and initial-state engineering as practical handles to program ferroic order in hierarchical ferroelectric domain structures.

Vasudevan, Rama K. [Oak Ridge National Laboratory

Maximizing Spaceflight Biological Data with Omics Analytics: The NASA GeneLab Database

NASA’s GeneLab includes an open-access repository of some 250+ omics datasets generated by biological experiments relevant to spaceflight including simulated cosmic radiation and microgravity. In order to maximize the intelligibility of these data, particularly for users with limited bioinformatics background, GeneLab has become a knowledgebase platform converting raw genetic and proteomic signatures found in flight samples into biological and physiological meanings. A large community of more than 100 scientists has rallied behind GeneLab and organized into four Analysis Working Groups (AWGs: Animal, Plant, Microbe, and Multi-Omics). Together, the AWGs have gained scientific recognition worldwide by establishing a consortium in charge of adopting new complex standards for data analysis workflows and omics sample processing in a rapidly evolving field. We will demonstrate the usage of the repository with smart search capability, an online controlled-access toolshed "Galaxy" to process user data with vetted standard workflows, a workspace for data sharing and a data submission portal with ontology control for better metadata curation. The GeneLab visualization portal will also be demonstrated, showing how anyone without formal training in bioinformatics can now browse the space biology omics data to discover new biology and potential solutions to improve life in space.

Sylvain Vincent Costes

GeneLab: The NASA System Biology Platform for Space Omics Repository, Analysis and Visualization

NASA’s GeneLab includes an open-access repository of some 250+ omics datasets generated by biological experiments relevant to spaceflight including simulated cosmic radiation and microgravity. In order to maximize the intelligibility of these data, particularly for users with limited bioinformatics background, GeneLab has become a knowledgebase platform converting raw genetic and proteomic signatures found in flight samples into biological and physiological meanings. A large community of more than 100 scientists has rallied behind GeneLab and organized into four Analysis Working Groups (AWGs: Animal, Plant, Microbe, and Multi-Omics). Together, the AWGs have gained scientific recognition worldwide by establishing a consortium in charge of adopting new complex standards for data analysis workflows and omics sample processing in a rapidly evolving field. We will demonstrate the usage of the repository with smart search capability, an online controlled-access toolshed "Galaxy" to process user data with vetted standard workflows, a workspace for data sharing and a data submission portal with ontology control for better metadata curation. The GeneLab visualization portal will also be demonstrated, showing how anyone without formal training in bioinformatics can now browse the space biology omics data to discover new biology and potential solutions to improve life in space.

GeneLab

Graduating to Postdoc: Information-Sharing in Support of Organizational Structures and Needs

The deployment of information-sharing systems in large organizations can significantly impact existing policies and procedures with regard to authority and control over information. Unless information-sharing systems explicitly support organizational structures and needs, these systems will be rejected summarily. The Postdoc system is a deployed Web-based information-sharing system created specifically to address organizational needs. Postdoc contains various organizational support features including a shared, globally navigable document space, as well as specialized access control, distributed administration, and mailing list features built around the key notion of hierarchical group structures. We review successes and difficulties in supporting organizational needs with Postdoc

Keller, Richard M.

Web Application Software for Ground Operations Planning Database (GOPDb) Management

A Web application facilitates collaborative development of the ground operations planning document. This will reduce costs and development time for new programs by incorporating the data governance, access control, and revision tracking of the ground operations planning data. Ground Operations Planning requires the creation and maintenance of detailed timelines and documentation. The GOPDb Web application was created using state-of-the-art Web 2.0 technologies, and was deployed as SaaS (Software as a Service), with an emphasis on data governance and security needs. Application access is managed using two-factor authentication, with data write permissions tied to user roles and responsibilities. Multiple instances of the application can be deployed on a Web server to meet the robust needs for multiple, future programs with minimal additional cost. This innovation features high availability and scalability, with no additional software that needs to be bought or installed. For data governance and security (data quality, management, business process management, and risk management for data handling), the software uses NAMS. No local copy/cloning of data is permitted. Data change log/tracking is addressed, as well as collaboration, work flow, and process standardization. The software provides on-line documentation and detailed Web-based help. There are multiple ways that this software can be deployed on a Web server to meet ground operations planning needs for future programs. The software could be used to support commercial crew ground operations planning, as well as commercial payload/satellite ground operations planning. The application source code and database schema are owned by NASA.

Lanham, Clifton

[X-33 Launch and Landing Facilities]

Sverdrup is responsible for the design, construction and activation of the X-33 Flight Operations Center at Edwards Air Force Base and for providing assistance in activating the X-33 Landing Sites. The past year has seen the completion of the construction of the X-33 Flight Operations Center. Construction was completed in December of 1998, with systems checkout and testing continuing into early 1999. Integration of the site with LMCMS and other partner-supplied systems began in December and will continue through rollout of the X-33 vehicle. The construction of the X-33 Launch Complex has been performed within the Edwards AFB and Air Force Research Laboratory (AFRL) systems with no substantial interference to either parties. A high level of cooperation exists between Sverdrup, Edwards AFB, and the Air Force Research Laboratory in the areas of access, training, security, and operations. There have been no conflicts between programs that have not been accommodated. Development of the landing sites is progressing with many of the modifications necessary underway. GSE commitments are in place. The personnel training program developed by Sverdrup for persons entering the launch site construction areas, was modified by Lockheed for use in training and access control to the Center during flight operations to maximize safety and minimize intrusion upon the environment. Close cooperation between Sverdrup, the construction workers, and the environmental biologist permitted construction to proceed in a timely fashion without harm to the wildlife, in particular, the Desert Tortoise. Although the entire X-33 site encompasses approximately 50 acres including a new access road, only the areas directly impacted by the construction were cleared to minimize the impact on the environment. A total of about 30 acres was actually disturbed.

Source record

Data Grid Management Systems

The "Grid" is an emerging infrastructure for coordinating access across autonomous organizations to distributed, heterogeneous computation and data resources. Data grids are being built around the world as the next generation data handling systems for sharing, publishing, and preserving data residing on storage systems located in multiple administrative domains. A data grid provides logical namespaces for users, digital entities and storage resources to create persistent identifiers for controlling access, enabling discovery, and managing wide area latencies. This paper introduces data grids and describes data grid use cases. The relevance of data grids to digital libraries and persistent archives is demonstrated, and research issues in data grids and grid dataflow management systems are discussed.

Moore, Reagan W.

Medical Data Architecture (MDA) Project Status

The Medical Data Architecture (MDA) project supports the Exploration Medical Capability (ExMC) risk to minimize or reduce the risk of adverse health outcomes and decrements in performance due to in-flight medical capabilities on human exploration missions. To mitigate this risk, the ExMC MDA project addresses the technical limitations identified in ExMC Gap Med 07: We do not have the capability to comprehensively process medically-relevant information to support medical operations during exploration missions. This gap identifies that the current in-flight medical data management includes a combination of data collection and distribution methods that are minimally integrated with on-board medical devices and systems. Furthermore, there are a variety of data sources and methods of data collection. For an exploration mission, the seamless management of such data will enable a more medically autonomous crew than the current paradigm. The medical system requirements are being developed in parallel with the exploration mission architecture and vehicle design. ExMC has recognized that in order to make informed decisions about a medical data architecture framework, current methods for medical data management must not only be understood, but an architecture must also be identified that provides the crew with actionable insight to medical conditions. This medical data architecture will provide the necessary functionality to address the challenges of executing a self-contained medical system that approaches crew health care delivery without assistance from ground support. Hence, the products supported by current prototype development will directly inform exploration medical system requirements.In fiscal year 2018, the MDA project developed Test Bed 2, the second iteration in a series of prototypes with functionality focused on data security through role-based access control and encryption, integration with One Portal exercise software and ingestion of an ultrasound Digital Imaging and Communications in Medicine (DICOM) file and image display. Test Bed 2 advances the medical data system architecture framework by providing these functionalities in a scalable system that maintained a layered, modular design. The architecture framework uses a data services approach with role-based access to data in a customized medical record system suitable for space exploration. These functionalities were demonstrated as part of the Next Space Technologies for Exploration Partnerships (NextSTEP) ground test demonstrated at the NASA Johnson Space Center Integrated Power, Avionics and Software (iPAS) facility. Interfacing to a Core Flight Software (CFS) system, the MDA system, using Consultative Committee for Space Data Systems (CCSDS) protocol, transferred an exercise file from the simulated flight MDA system to a mirrored MDA system on the ground through the CFS system. The selection of data sources and demonstrations enabled the team to address stakeholder concerns throughout the development process. In the next iteration, the MDA team will work with stakeholders to identify additional relevant functionalities to further advance system data models, standards and principles that will inform the medical system requirements development.

medical data architecture

Performance analysis of FDDI

The Fiber Distributed Data Interface (FDDI) is an imerging ANSI and ISO standard for a 100 megabit per second fiber optic token ring. The performance of the FDDI media access control protocol is analyzed using a simulation developed at NASA Ames. Both analyses using standard measures of performance (including average delay for asynchronous traffic, channel utilization, and transmission queue length) and analyses of characteristics of ring behavior which can be attributed to constraints imposed by the timed token protocol on token holding time (including bounded token rotation time, support for synchronous traffic, and fairness of channel access for nodes transmitting asynchronous traffic) are included.

Johnson, Marjory J.

AQDrop Quantum Service (AQDrop) v1.0

AQDrop is a job management system designed to streamline access to the Advanced Quantum Testbed (AQT) at NERSC (National Energy Research Scientific Computing Center). It serves as a centralized middleware layer between researchers and quantum processing hardware. Key Features: AQDrop provides a FastAPI-based server backed by PostgreSQL for job submission, queue management, and role-based access control (members, operators, and administrators). Users submit Qiskit circuits via JSON payloads, which are queued, dispatched to the QPU through the Qubic API, and returned as measurement counts. A Python client library and web dashboard round out the interface options. Primary Use: Researchers submit quantum circuit jobs from a laptop or login node; an operator client executes those jobs on the AQT's physical QPU and returns results — all coordinated through the central API. Advantages: Compared to ad-hoc or direct hardware access, AQDrop adds structured queue management, auditable job-status tracking and OAuth2 authentication — reducing scheduling conflicts and unauthorized access. Its containerized deployment also improves reproducibility and scalability. Overall, AQDrop functions as a purpose-built quantum job broker tailored to NERSC's specific hardware and institutional access requirements.

Caplinger, Evan [Lawrence Berkeley National Labora

Evolution of Web Services in EOSDIS: Search and Order Metadata Registry (ECHO)

During 2005 through 2008, NASA defined and implemented a major evolutionary change in it Earth Observing system Data and Information System (EOSDIS) to modernize its capabilities. This implementation was based on a vision for 2015 developed during 2005. The EOSDIS 2015 Vision emphasizes increased end-to-end data system efficiency and operability; increased data usability; improved support for end users; and decreased operations costs. One key feature of the Evolution plan was achieving higher operational maturity (ingest, reconciliation, search and order, performance, error handling) for the NASA s Earth Observing System Clearinghouse (ECHO). The ECHO system is an operational metadata registry through which the scientific community can easily discover and exchange NASA's Earth science data and services. ECHO contains metadata for 2,726 data collections comprising over 87 million individual data granules and 34 million browse images, consisting of NASA s EOSDIS Data Centers and the United States Geological Survey's Landsat Project holdings. ECHO is a middleware component based on a Service Oriented Architecture (SOA). The system is comprised of a set of infrastructure services that enable the fundamental SOA functions: publish, discover, and access Earth science resources. It also provides additional services such as user management, data access control, and order management. The ECHO system has a data registry and a services registry. The data registry enables organizations to publish EOS and other Earth-science related data holdings to a common metadata model. These holdings are described through metadata in terms of datasets (types of data) and granules (specific data items of those types). ECHO also supports browse images, which provide a visual representation of the data. The published metadata can be mapped to and from existing standards (e.g., FGDC, ISO 19115). With ECHO, users can find the metadata stored in the data registry and then access the data either directly online or through a brokered order to the data archive organization. ECHO stores metadata from a variety of science disciplines and domains, including Climate Variability and Change, Carbon Cycle and Ecosystems, Earth Surface and Interior, Atmospheric Composition, Weather, and Water and Energy Cycle. ECHO also has a services registry for community-developed search services and data services. ECHO provides a platform for the publication, discovery, understanding and access to NASA s Earth Observation resources (data, service and clients). In their native state, these data, service and client resources are not necessarily targeted for use beyond their original mission. However, with the proper interoperability mechanisms, users of these resources can expand their value, by accessing, combining and applying them in unforeseen ways.

Mitchell, Andrew

Smart Inverters, Dumb Risk: Taking Control of IBR Security in the Digital Age

This presentation addresses the security challenges posed by Inverter-Based Resources (IBRs) in the modern energy landscape. The presentation highlights the vulnerabilities and risks associated with IBRs, including the potential for cyber-attacks, the impact of insecure defaults, and the systemic risks posed by supply chain dependencies. Key topics covered include: 1) The increasing digital transformation in energy systems and the associated security risks. 2) Specific vulnerabilities in IBRs, including weak passwords, hardcoded credentials, and insecure web application interfaces. 3) The implications of persistent connectivity and the strategic risks posed by foreign-manufactured components. 4) The role of regulatory frameworks, such as NERC CIP, in addressing these challenges and the limitations of current oversight. 5) Practical solutions for mitigating risks, including secure design practices, vendor risk assessments, and the importance of strong passwords and role-based access control. The presentation underscores the necessity of a comprehensive, system-of-systems approach to securing IBRs, emphasizing the need for collaboration across various stakeholders, including operators, developers, and regulators, to ensure the resilience and security of the energy grid.

24 - POWER TRANSMISSION AND DISTRIBUTION

DMFS: A Data Migration File System for NetBSD

I have recently developed dmfs, a Data Migration File System, for NetBSD. This file system is based on the overlay file system, which is discussed in a separate paper, and provides kernel support for the data migration system being developed by my research group here at NASA/Ames. The file system utilizes an underlying file store to provide the file backing, and coordinates user and system access to the files. It stores its internal meta data in a flat file, which resides on a separate file system. Our data migration system provides archiving and file migration services. System utilities scan the dmfs file system for recently modified files, and archive them to two separate tape stores. Once a file has been doubly archived, files larger than a specified size will be truncated to that size, potentially freeing up large amounts of the underlying file store. Some sites will choose to retain none of the file (deleting its contents entirely from the file system) while others may choose to retain a portion, for instance a preamble describing the remainder of the file. The dmfs layer coordinates access to the file, retaining user-perceived access and modification times, file size, and restricting access to partially migrated files to the portion actually resident. When a user process attempts to read from the non-resident portion of a file, it is blocked and the dmfs layer sends a request to a system daemon to restore the file. As more of the file becomes resident, the user process is permitted to begin accessing the now-resident portions of the file. For simplicity, our data migration system divides a file into two portions, a resident portion followed by an optional non-resident portion. Also, a file is in one of three states: fully resident, fully resident and archived, and (partially) non-resident and archived. For a file which is only partially resident, any attempt to write or truncate the file, or to read a non-resident portion, will trigger a file restoration. Truncations and writes are blocked until the file is fully restored so that a restoration which only partially succeed does not leave the file in an indeterminate state with portions existing only on tape and other portions only in the disk file system. We chose layered file system technology as it permits us to focus on the data migration functionality, and permits end system administrators to choose the underlying file store technology. We chose the overlay layered file system instead of the null layer for two reasons: first to permit our layer to better preserve meta data integrity and second to prevent even root processes from accessing migrated files. This is achieved as the underlying file store becomes inaccessible once the dmfs layer is mounted. We are quite pleased with how the layered file system has turned out. Of the 45 vnode operations in NetBSD, 20 (forty-four percent) required no intervention by our file layer - they are passed directly to the underlying file store. Of the twenty five we do intercept, nine (such as vop_create()) are intercepted only to ensure meta data integrity. Most of the functionality was concentrated in five operations: vop_read, vop_write, vop_getattr, vop_setattr, and vop_fcntl. The first four are the core operations for controlling access to migrated files and preserving the user experience. vop_fcntl, a call generated for a certain class of fcntl codes, provides the command channel used by privileged user programs to communicate with the dmfs layer.

Studenmund, William