Search NASA⌕ Search

SEARCH · Search NASA

Results for “security architecture”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Virtual Power Plant Architecture and Resilient Design

Virtual Power Plants (VPPs) represent a fundamental shift in electric grid operations, aggregating distributed energy resources (DERs) such as solar panels and battery storage to deliver utility-scale grid services traditionally provided by centralized power plants. This report examines the unique architectural, operational, and digital assurance considerations that distinguish VPPs from conventional utility infrastructure as they scale from pilot projects to mainstream deployment across the United States. While VPPs offer significant opportunities for grid modernization and enhanced flexibility, their distributed, multi-stakeholder architecture introduces distinct security challenges that differ fundamentally from traditional generation facilities. The analysis identifies risks in VPP operations, including device-level security gaps, platform vulnerabilities, and communication protocol weaknesses that create expanded attack surfaces compared to centralized power plants. Through examination of real-world incidents and emerging threat patterns, the report demonstrates how some VPPs' reliance on consumer-owned devices, public internet infrastructure, and complex vendor ecosystems require new approaches to digital assurance and operational security. The findings provide practical guidance for utilities, regulators, and aggregators to implement robust security frameworks and operational best practices essential for maintaining grid reliability as VPP deployment accelerates under the Federal Energy Regulatory Commission (FERC) Order 2222 and related regulatory initiatives.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Technology for a NASA Space-Based Science Operations Grid

This viewgraph representation presents an overview of a proposal to develop a space-based operations grid in support of space-based science experiments. The development of such a grid would provide a dynamic, secure and scalable architecture based on standards and next-generation reusable software and would enable greater science collaboration and productivity through the use of shared resources and distributed computing. The authors propose developing this concept for use on payload experiments carried aboard the International Space Station. Topics covered include: grid definitions, portals, grid development and coordination, grid technology and potential uses of such a grid.

Bradford, Robert N.↗

The Development of a Data Archive and Analysis Tools for WIRE

Contents include the following: mission description and system identification; environment description; system architectural description; system security requirements; organization and resources; and ditscap plan. Appendix A, acronym list. Appendix B, definitions. Appendix C, references.

Buzasi, D.↗

Technical Challenges and Opportunities of Centralizing Space Science Mission Operations (SSMO) at NASA Goddard Space Flight Center

The NASA Goddard Space Science Mission Operations project (SSMO) is performing a technical cost-benefit analysis for centralizing and consolidating operations of a diverse set of missions into a unified and integrated technical infrastructure. The presentation will focus on the notion of normalizing spacecraft operations processes, workflows, and tools. It will also show the processes of creating a standardized open architecture, creating common security models and implementations, interfaces, services, automations, notifications, alerts, logging, publish, subscribe and middleware capabilities. The presentation will also discuss how to leverage traditional capabilities, along with virtualization, cloud computing services, control groups and containers, and possibly Big Data concepts.

Science↗

Provider of Services for Urban Air Mobility (PSU) Prototype Simulation (X5) Final Report

Urban Air Mobility (UAM) is a new air transportation service concept to carry passengers or cargo in metropolitan areas, leveraged by innovative aircraft and air traffic automation technologies. NASA has conducted a series of simulations, called the X-series simulation, to evaluate the UAM concept of operations and support the development of airspace procedures and services for UAM operations. The simulation called “X5” was conducted in 2023 to test a Provider of Services for UAM (PSU) prototype developed by NASA for UAM flight planning, strategic conflict management support, and data exchange between UAM operators. In this simulation, two strategic conflict management capabilities, Demand-Capacity Balancing and Sequencing and Scheduling, were further investigated. This document describes the UAM system architecture modeled, the X5 simulation environment to be executed (e.g., traffic scenario and UAM airspace construct), and the strategic conflict management processes developed and evaluated in this study. Then, the simulation results are provided using several system performance metrics, such as the number of operations planned and activated, demand-capacity imbalances detected and resolved, and pre-departure delays. Based on these metrics, the test findings and lessons learned from this simulation are discussed. NASA developed a PSU prototype as part of a reference implementation of UAM system architecture and evolved strategic conflict management capabilities for UAM operations from the previous collaborative simulations with industry partners. Below is the summary of the achievements: - Aligned NASA’s UAM reference architecture with the FAA’s UAM ConOps notional architecture - Extended UAM airspace management capabilities to include 1) Demand-Capacity Balancing (DCB) to ensure operators coordinate planned usage of shared vertiports, and 2) Sequencing and Scheduling (S&S) at UAM corridor entry and exit points to help facilitate an orderly flow of traffic - Defined the PSU information exchange APIs and requirements towards informing industry standards - Developed and tested a NASA PSU prototype as reference implementation to validate the requirements and APIs - Developed a prototype service connecting NASA’s PSU and the FAA system for testing future PSU-ATM interface requirements - Tested NASA-developed assumptions for UAM operations such as airspace design, procedures, vehicle performance, and strategic conflict management methods to inform future Cooperative Operating Practices (COPs) development with industry - Evaluated system performance metrics such as number of simultaneous operations and ground delays that can help define system-level requirements. The simulation results showed that the UAM traffic demand could be managed to minimize the needs of tactical separation provision with ground delays assigned by DCB and S&S. These accomplishments and the lessons learned from the PSU Prototype X5 simulation activities will be valuable inputs for the Air Mobility Pathfinders (AMP) project, which is NASA’s new project to create and evaluate a reference architecture for safe, secure, and scalable UAM operations.

Simulation↗

Operational Concepts for a Generic Space Exploration Communication Network Architecture

This document is one of three. It describes the Operational Concept (OpsCon) for a generic space exploration communication architecture. The purpose of this particular document is to identify communication flows and data types. Two other documents accompany this document, a security policy profile and a communication architecture document. The operational concepts should be read first followed by the security policy profile and then the architecture document. The overall goal is to design a generic space exploration communication network architecture that is affordable, deployable, maintainable, securable, evolvable, reliable, and adaptable. The architecture should also require limited reconfiguration throughout system development and deployment. System deployment includes: subsystem development in a factory setting, system integration in a laboratory setting, launch preparation, launch, and deployment and operation in space.

networking↗

Space Station needs, attributes, and architectural option study

Potential user interest and requirements for a manned space station are examined for space and applications missions, commercial missions, technology demonstration missions, space operations missions, and national security missions. Approaches to architectural options, candidate payloads, and technology drivers are considered. Mission imposed requirements for the space operations center are also considered.

Source record↗

Implementation and Demonstration of the Digital Twin Certification System Remote Operations Framework

Microreactors are one promising advanced-reactor concept being pursued by the nuclear industry. They are distinguished by a relatively low power output of 20 MWth or less. These microreactors are intended for deployment in applications where conventional small-capacity power solutions, such as diesel generators, are either economically unfeasible or logistically challenging. Such applications include providing electric power and/or heat for remote communities, mining sites, defense installations, and humanitarian and disaster-relief missions. An important feature for the successful deployment of microreactors is their capability to be operated remotely. This capability can significantly reduce staffing costs by eliminating the need for licensed operators to be physically present at each reactor site. Instead, operators can be centralized in a single remote operations center placed in an economically advantageous location, thereby optimizing resources by consolidating expertise and enhancing operational efficiency. However, the implementation of a remote operation system for nuclear reactors raises new concerns regarding the security, reliability, and resilience of such a system. One way in which remote operations can be supported in a manner that maintains system security, reliability, and resilience is through the use of digital twins in a novel framework designed to verify and validate sensor data and commands communicated between the remote operations center and reactor. This framework, known as the Digital Twin Certification System (DTCS), has previously been proposed as an operations architecture that can bring security and resiliency levels of remote nuclear-reactor operations to a level acceptable for commercial deployment. This paper moves the proposed DTCS architecture from concept to reality by presenting the implementation and testing of the system. The rationale and implementation of the DTCS using tools such as DeepLynx and Apache Airflow, is covered in-depth. This is followed by a demonstration of the DTCS by applying the implemented system architecture to the Single Primary Heat Extraction and Removal Emulator, a small-scale non-nuclear test bed that emulates thermal behavior of a microreactor. The demonstration includes both normal and abnormal operating scenarios to highlight how the DTCS can increase the security, reliability, and resilience of a remote operations system.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Implementation and Demonstration of the Digital Twin Certification System Remote Operations Framework

Microreactors are one promising advanced-reactor concept being pursued by the nuclear industry. They are distinguished by a relatively low power output of 20 MWth or less. These microreactors are intended for deployment in applications where conventional small-capacity power solutions, such as diesel generators, are either economically unfeasible or logistically challenging. Such applications include providing electric power and/or heat for remote communities, mining sites, defense installations, and humanitarian and disaster-relief missions. An important feature for the successful deployment of microreactors is their capability to be operated remotely. This capability can significantly reduce staffing costs by eliminating the need for licensed operators to be physically present at each reactor site. Instead, operators can be centralized in a single remote operations center placed in an economically advantageous location, thereby optimizing resources by consolidating expertise and enhancing operational efficiency. However, the implementation of a remote operation system for nuclear reactors raises new concerns regarding the security, reliability, and resilience of such a system. One way in which remote operations can be supported in a manner that maintains system security, reliability, and resilience is through the use of digital twins in a novel framework designed to verify and validate sensor data and commands communicated between the remote operations center and reactor. This framework, known as the Digital Twin Certification System (DTCS), has previously been proposed as an operations architecture that can bring security and resiliency levels of remote nuclear-reactor operations to a level acceptable for commercial deployment. This paper moves the proposed DTCS architecture from concept to reality by presenting the implementation and testing of the system. The rationale and implementation of the DTCS using tools such as DeepLynx and Apache Airflow, is covered in-depth. This is followed by a demonstration of the DTCS by applying the implemented system architecture to the Single Primary Heat Extraction and Removal Emulator, a small-scale non-nuclear test bed that emulates thermal behavior of a microreactor. The demonstration includes both normal and abnormal operating scenarios to highlight how the DTCS can increase the security, reliability, and resilience of a remote operations system.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

An Architectural Survey of the U12G Tunnel Historic District, Nevada National Security Site, Nye County, Nevada

The U.S. Department of Energy (DOE), in conjunction with the National Nuclear Security Administration Nevada Field Office (NNSA/NFO), proposes to demolish six buildings and three storage areas located at the U12g Tunnel portal area in Area 12 of the Nevada National Security Site (NNSS). The buildings are 12-358 (Signal Vault); 12-201800 (Storage Quonset Hut); 12-202555 (Walker Shack); 12-868 (Pipe Assembly); 12-B100933 (Electrical Shop); 12-B100944 (Conference Room); and Storage Area 1; Storage Area 2; and Storage Area 3. The buildings and storage areas were selected for demolition as part of the DOE’s Real Property Efficiency Plan to reduce the footprint of unused and non-operational facilities on the NNSS. They are all vacant and have no proposed uses for current or upcoming NNSS missions. Demolition activities constitute an undertaking subject to review under Section 106 of the National Historic Preservation Act (NHPA) (54 United States Code [USC] § 306101) and its implementing regulations, 36 Code of Federal Regulations (CFR) Part 800. Identification efforts began with resources proposed for demolition in federal Fiscal Year (FY) 23. Four buildings were proposed to be demolished in FY23 (12-358, 12-868, 12-201800, and 12-202555). These buildings and the U12g Tunnel Historic District (SHPO No. D444) were recorded in Identification, Evaluation, and Finding of Adverse Effect for the Proposed Demolition of Five Buildings in Area 12, Nevada National Security Site, Nye County, Nevada (Menocal et al. 2023). Identification efforts indicated three buildings (12-358, 12-201800, and 12-868) supported nuclear testing in the U12g Tunnel. The fourth building post-dated the use of U12g Tunnel for nuclear testing activities. The report recommended that three of the four buildings (12-358, 12-201800, 12-868) and the U12g Tunnel Historic District may be eligible for the National Register of Historic Places (NRHP). The report also found that the undertaking would have an adverse effect on the three buildings and on the historic district. The Nevada State Historic Preservation Office (SHPO) concurred with the report’s findings (Reed 2023). The U12g Tunnel was determined eligible as a historic district under the Secretary of the Interior’s (SOI) Significance Criterion A, at the local level, in the context of the Cold War as an underground testing environment for the development of nuclear weapons and to assess the effects of a nuclear explosion on materials and equipment with a period of significance from 1959 to 1971. It was also determined eligible under Significance Criterion C for embodying the distinctive characters of a horizontal tunnel complex used for nuclear testing and as a significant and distinguishable entity. The three buildings were determined to be contributing elements of the district. The undertaking was expanded with the addition of two buildings and three storage areas proposed to be demolished and located within U12g Tunnel Historic District in FY24. These five resources (12-B100933, 12-B100944, and Storage Areas 1, 2, and 3) were recorded in Supplemental Identification, Evaluation, and Finding of Effect for Additional Proposed Demolition at U12g Tunnel, Area 12, Nevada national Security Site, Nye County, Nevada (Brannan et al. 2024). Identification efforts indicated that the two buildings and Storage Area 1 supported nuclear testing in the U12g Tunnel. Storage Area 1 and Storage Area 2 post-dated the nuclear testing activities at U12g Tunnel and were not recommended as contributing elements to the district. The report also found that the undertaking would have an adverse effect on the newly identified buildings and one storage area and on the historic district. The SHPO concurred that the expanded undertaking would result in adverse effects to historic properties (Reed 2025). To resolve these adverse effects, NNSA/NFO, in consultation with the SHPO, is following standard mitigation as stipulated in the 2024 Programmatic Agreement DE-GM58-22NA25554 Among the U.S. Department of Energy and the Nevada State Historic Preservation Officer and the Advisory Council on Historic Preservation Concerning the Protection of Historic Properties on the Nevada National Security Site, Nye County, Nevada (hereafter referred to as the NNSS PA). The standard mitigation measures are outlined in Appendix D of the NNSS PA. As such, this architectural survey has been prepared in accordance with Appendix D of the NNSS PA and follows the report format outlined in Appendix F. It includes a historic context that describes the district’s origin, history, and support functions, its significance in the context of nuclear testing on the NNSS, and identifies contributing and non-contributing elements within the district. The report is accompanied by Architectural Resource Assessment (ARA) forms for individual resources and a Historic District Resource Assessment (HDRA) for the U12g Tunnel Historic District. In total, this architectural report identified 32 primary resources within the district boundary. Six of the primary resources were previously identified as contributing elements. An additional 17 resources are recommended as contributing elements to the district for a total of 23 contributing elements. The other nine resources identified are recommended as non-contributing elements to the district.

12-201800↗

5G Communications in Nuclear: Potential Use Cases and Security Considerations

As fifth-generation (5G) communications continues to revolutionize the future of wireless technology, there is growing demand to utilize its benefits for critical infrastructures such as nuclear power plants (NPPs). In regard to achieving full automation and control in the operation of existing and future nuclear reactors, the unique capabilities of 5G can bring several potential advantages over other wireless technologies. However, a deep investigation is needed for the availability and security of 5G communications under various NPP operational scenarios. This article examines how 5G security capabilities can be architecturally deployed in nuclear applications so as to replace existing communication infrastructures. We discuss the current use of all wireless technologies in NPPs with their key features. Consequently, we investigated several NPP use cases in which 5G offers potential advantages but entails specific security considerations. The present article covers the characteristics of 5G communications, general challenges to its application in nuclear, and the security gaps that need to be addressed. We also highlight certain 5G security-by-design features that can help addressing current stringent NPP requirements. In addition, we discuss some future research direction that can facilitate the implementation of 5G in a nuclear facility. The findings presented herein can help foster 5G deployment in NPPs, thus enabling secured data transmission, cost savings, and increased operational efficiency with enhanced reliability.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

CORBASec Used to Secure Distributed Aerospace Propulsion Simulations

The NASA Glenn Research Center and its industry partners are developing a Common Object Request Broker (CORBA) Security (CORBASec) test bed to secure their distributed aerospace propulsion simulations. Glenn has been working with its aerospace propulsion industry partners to deploy the Numerical Propulsion System Simulation (NPSS) object-based technology. NPSS is a program focused on reducing the cost and time in developing aerospace propulsion engines. It was developed by Glenn and is being managed by the NASA Ames Research Center as the lead center reporting directly to NASA Headquarters' Aerospace Technology Enterprise. Glenn is an active domain member of the Object Management Group: an open membership, not-for-profit consortium that produces and manages computer industry specifications (i.e., CORBA) for interoperable enterprise applications. When NPSS is deployed, it will assemble a distributed aerospace propulsion simulation scenario from proprietary analytical CORBA servers and execute them with security afforded by the CORBASec implementation. The NPSS CORBASec test bed was initially developed with the TPBroker Security Service product (Hitachi Computer Products (America), Inc., Waltham, MA) using the Object Request Broker (ORB), which is based on the TPBroker Basic Object Adaptor, and using NPSS software across different firewall products. The test bed has been migrated to the Portable Object Adaptor architecture using the Hitachi Security Service product based on the VisiBroker 4.x ORB (Borland, Scotts Valley, CA) and on the Orbix 2000 ORB (Dublin, Ireland, with U.S. headquarters in Waltham, MA). Glenn, GE Aircraft Engines, and Pratt & Whitney Aircraft are the initial industry partners contributing to the NPSS CORBASec test bed. The test bed uses Security SecurID (RSA Security Inc., Bedford, MA) two-factor token-based authentication together with Hitachi Security Service digital-certificate-based authentication to validate the various NPSS users. The test bed is expected to demonstrate NPSS CORBASec-specific policy functionality, confirm adequate performance, and validate the required Internet configuration in a distributed collaborative aerospace propulsion environment.

Blaser, Tammy M.↗

Towards Behavioral Reflexion Models

Software architecture has become essential in the struggle to manage today s increasingly large and complex systems. Software architecture views are created to capture important system characteristics on an abstract and, thus, comprehensible level. As the system is implemented and later maintained, it often deviates from the original design specification. Such deviations can have implication for the quality of the system, such as reliability, security, and maintainability. Software architecture compliance checking approaches, such as the reflexion model technique, have been proposed to address this issue by comparing the implementation to a model of the systems architecture design. However, architecture compliance checking approaches focus solely on structural characteristics and ignore behavioral conformance. This is especially an issue in Systems-of- Systems. Systems-of-Systems (SoS) are decompositions of large systems, into smaller systems for the sake of flexibility. Deviations of the implementation to its behavioral design often reduce the reliability of the entire SoS. An approach is needed that supports the reasoning about behavioral conformance on architecture level. In order to address this issue, we have developed an approach for comparing the implementation of a SoS to an architecture model of its behavioral design. The approach follows the idea of reflexion models and adopts it to support the compliance checking of behaviors. In this paper, we focus on sequencing properties as they play an important role in many SoS. Sequencing deviations potentially have a severe impact on the SoS correctness and qualities. The desired behavioral specification is defined in UML sequence diagram notation and behaviors are extracted from the SoS implementation. The behaviors are then mapped to the model of the desired behavior and the two are compared. Finally, a reflexion model is constructed that shows the deviations between behavioral design and implementation. This paper discusses the approach and shows how it can be applied to investigate reliability issues in SoS.

Ackermann, Christopher↗

Fusing Edge Computing with Transport Security by Leveraging the Controller Area Network Transport Security Tracking and Reporting (C-STAR) Unit

Rapid advances in embedded system complexity and capability provides exciting opportunities for transportation security deployment. Manufacturers and developers of these embedded systems continue to provide lower cost and more powerful solutions that can be leveraged by researchers and engineers. Furthermore, deploying these devices at the “edge” of the Internet-of-Things (IoT) infrastructure provides opportunities for highly capable applications in transport security. In an edge computation architecture, the device is co-located at the source of the data in the larger IoT structure – this provides computational capability at the location directly where the data is collected. For shipment transport security, this provides a direct compute node for digestion of data and mitigation actions in real-time. In our application, the vehicle provides a significant amount of this data that can be processed in real-time via the Controller Area Network Transport Security Tracking and Reporting (C-STAR) edge device. Utilization of a computational node located on the vehicle, such as the C-STAR, capitalizes on previously discussed opportunities of edge architectures. In this paper, we will discuss this security solution’s usability, current deployments, and scalability to further applications in transport security. First, we will cover the supported vehicle platforms that can leverage the C-STAR technology. This will be particularly relevant to medium- and heavy-duty vehicles transporting high-risk shipments. Second, we will speak to current deployments of the C-STAR that are ongoing. Finally, we will discuss additional areas for expansion such as maturing the onboard algorithms through continuing collaborations.

Cook, Adian [ORNL] (ORCID:0000000160825395)↗

ARIES and ADMS Test Bed Overview and Updates

This presentation provides an overview and updates on the National Renewable Energy Laboratory's Advanced Research on Integrated Energy Systems (ARIES) platform and Advanced Distribution Management System (ADMS Test Bed).

ADMS↗

A Hybrid Power Management (HPM) Based Vehicle Architecture

Society desires vehicles with reduced fuel consumption and reduced emissions. This presents a challenge and an opportunity for industry and the government. The NASA John H. Glenn Research Center (GRC) has developed a Hybrid Power Management (HPM) based vehicle architecture for space and terrestrial vehicles. GRC's Electrical and Electromagnetics Branch of the Avionics and Electrical Systems Division initiated the HPM Program for the GRC Technology Transfer and Partnership Office. HPM is the innovative integration of diverse, state-of-the-art power devices in an optimal configuration for space and terrestrial applications. The appropriate application and control of the various power devices significantly improves overall system performance and efficiency. The basic vehicle architecture consists of a primary power source, and possibly other power sources, providing all power to a common energy storage system, which is used to power the drive motors and vehicle accessory systems, as well as provide power as an emergency power system. Each component is independent, permitting it to be optimized for its intended purpose. This flexible vehicle architecture can be applied to all vehicles to considerably improve system efficiency, reliability, safety, security, and performance. This unique vehicle architecture has the potential to alleviate global energy concerns, improve the environment, stimulate the economy, and enable new missions.

Eichenberg, Dennis J.↗

Secure Network-Centric Aviation Communication (SNAC)

The existing National Airspace System (NAS) communications capabilities are largely unsecured, are not designed for efficient use of spectrum and collectively are not capable of servicing the future needs of the NAS with the inclusion of new operators in Unmanned Aviation Systems (UAS) or On Demand Mobility (ODM). SNAC will provide a ubiquitous secure, network-based communications architecture that will provide new service capabilities and allow for the migration of current communications to SNAC over time. The necessary change in communication technologies to digital domains will allow for the adoption of security mechanisms, sharing of link technologies, large increase in spectrum utilization, new forms of resilience and redundancy and the possibly of spectrum reuse. SNAC consists of a long term open architectural approach with increasingly capable designs used to steer research and development and enable operating capabilities that run in parallel with current NAS systems.

Communications↗