Search NASASearch

SEARCH · Search NASA

Results for “security verification”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Software assurance standard

This standard specifies the software assurance program for the provider of software. It also delineates the assurance activities for the provider and the assurance data that are to be furnished by the provider to the acquirer. In any software development effort, the provider is the entity or individual that actually designs, develops, and implements the software product, while the acquirer is the entity or individual who specifies the requirements and accepts the resulting products. This standard specifies at a high level an overall software assurance program for software developed for and by NASA. Assurance includes the disciplines of quality assurance, quality engineering, verification and validation, nonconformance reporting and corrective action, safety assurance, and security assurance. The application of these disciplines during a software development life cycle is called software assurance. Subsequent lower-level standards will specify the specific processes within these disciplines.

Source record

Roxana Paramo Ramirez: MSIIP 2025-2026 Internship [Poster]

At Sandia National Laboratories, there is a high level of importance placed on identifying and developing solutions to the nation’s current and future security problems. One of these problem would be hardware electronics validation and verification.

42 ENGINEERING

PROACTIVE Focus Area 4: Structured Decision Metrics Analysis (Final Report)

A structured decision metrics analysis was developed as one of the tasks under PROACTIVE’s Focus Area 4 (FA4) and used structured decision metrics for processes, items, and facilities (PIF) to determine the efficacy of an M&V system in meeting treaty goals and technical objectives. The method starts with the functional decomposition of a “treaty” with the M&V system overlaid on it. A Functional Decomposition Rubric (FDR) for each PIF is used to determine a score ranging from 0 (weak) to 4 (strong) for assurance, security, and burden. The individual scores are combined to provide an overall Verification System Score (VSS) which assesses the overall verification system’s suitability given goals; scores for each step of the process are also given. The outcome of the evaluation is to identify needs or modifications to the enterprise model, verification system, or proposed testbed capabilities. VeriScore was used to evaluate FA4’s Spiral 0 exercise; those results are included in this report. The VeriScore and FDR framework can also be used in a non-treaty environment, as any goal/objective/method structure will work, thus expanding its applicability beyond traditional arms control structures.

99 GENERAL AND MISCELLANEOUS

Navigating United States Standards and Regulation for Digital Energy Systems

This report provides an analysis of the U.S. standards and regulatory landscape for digital energy systems, focusing on cybersecurity, safety, and reliability requirements. It examines the interplay between federal mandates, state regulations, voluntary industry standards, and utility-specific policies, highlighting critical gaps between compliance and real-world risk mitigation. While NERC CIP standards enforce cybersecurity for Bulk Electric System assets, distribution-level infrastructure and emerging technologies often fall outside mandatory oversight, creating vulnerabilities. The report identifies systemic challenges such as reliance on self-attestation, uneven state adoption of safety codes, and lagging standards for advanced technologies like battery energy storage and inverter-based resources. Through a detailed gap analysis, it underscores the urgency of proactive risk-based approaches, independent verification, and strategic engagement with state and federal entities. Recommendations include adopting tiered security frameworks, strengthening procurement practices, and addressing emerging technology risks to ensure resilient and secure digital energy infrastructure. This guidance is intended for utilities, regulators, and stakeholders navigating compliance obligations and seeking to enhance cybersecurity and safety beyond minimum standards.

24 - POWER TRANSMISSION AND DISTRIBUTION

Tropospheric Airborne Meteorological Data Reporting (TAMDAR) Sensor Validation and Verification on National Oceanographic and Atmospheric Administration (NOAA) Lockheed WP-3D Aircraft

As part of the National Aeronautics and Space Administration's Aviation Safety and Security Program, the Tropospheric Airborne Meteorological Data Reporting project (TAMDAR) developed a low-cost sensor for aircraft flying in the lower troposphere. This activity was a joint effort with support from Federal Aviation Administration, National Oceanic and Atmospheric Administration, and industry. This paper reports the TAMDAR sensor performance validation and verification, as flown on board NOAA Lockheed WP-3D aircraft. These flight tests were conducted to assess the performance of the TAMDAR sensor for measurements of temperature, relative humidity, and wind parameters. The ultimate goal was to develop a small low-cost sensor, collect useful meteorological data, downlink the data in near real time, and use the data to improve weather forecasts. The envisioned system will initially be used on regional and package carrier aircraft. The ultimate users of the data are National Centers for Environmental Prediction forecast modelers. Other users include air traffic controllers, flight service stations, and airline weather centers. NASA worked with an industry partner to develop the sensor. Prototype sensors were subjected to numerous tests in ground and flight facilities. As a result of these earlier tests, many design improvements were made to the sensor. The results of tests on a final version of the sensor are the subject of this report. The sensor is capable of measuring temperature, relative humidity, pressure, and icing. It can compute pressure altitude, indicated air speed, true air speed, ice presence, wind speed and direction, and eddy dissipation rate. Summary results from the flight test are presented along with corroborative data from aircraft instruments.

Tsoucalas, George

Systems integration for the Kennedy Space Center (KSC) Robotics Applications Development Laboratory (RADL)

A laboratory for developing robotics technology for hazardous and repetitive Shuttle and payload processing activities is discussed. An overview of the computer hardware and software responsible for integrating the laboratory systems is given. The center's anthropomorphic robot is placed on a track allowing it to be moved to different stations. Various aspects of the laboratory equipment are described, including industrial robot arm control, smart systems integration, the supervisory computer, programmable process controller, real-time tracking controller, image processing hardware, and control display graphics. Topics of research include: automated loading and unloading of hypergolics for space vehicles and payloads; the use of mobile robotics for security, fire fighting, and hazardous spill operations; nondestructive testing for SRB joint and seal verification; Shuttle Orbiter radiator damage inspection; and Orbiter contour measurements. The possibility of expanding the laboratory in the future is examined.

Davis, V. Leon

Evaluation of Real-Time Mitigation Techniques forCyber Security in IEC 61850 / IEC 62351Substations

This paper presents the design logic and implementation aspects of three potential real-time mitigation techniques capable of countering GOOSE-based attacks: (i) IEC 62351-compliant message authentication code (MAC) scheme, (ii) a semantics-enforced rule- based intrusion detection system (IDS), and (iii) a hybrid approach integrating both MAC verification and Intrusion Detection System (IDS). A comparative evaluation of these real-time mitigation approaches is conducted using a cyber-physical system(CPS) security testbed. The results show that the hybrid integration significantly enhances mitigation capability. Furthermore, the processing delays of all three methods remain within the strict delivery requirements of GOOSE communication. The study also identifies limitations that none of the techniques can fully address, highlighting areas for future work.

Liu, Chen-Ching [Virginia Polytechnic Inst. and St

Certified randomness using a trapped-ion quantum processor

Although quantum computers can perform a wide range of practically important tasks beyond the abilities of classical computers, realizing this potential remains a challenge. An example is to use an untrusted remote device to generate random bits that can be certified to contain a certain amount of entropy. Certified randomness has many applications but is impossible to achieve solely by classical computation. Here we demonstrate the generation of certifiably random bits using the 56-qubit Quantinuum H2-1 trapped-ion quantum computer accessed over the Internet. Our protocol leverages the classical hardness of recent random circuit sampling demonstrations: a client generates quantum ‘challenge’ circuits using a small randomness seed, sends them to an untrusted quantum server to execute and verifies the results of the server. We analyse the security of our protocol against a restricted class of realistic near-term adversaries. Using classical verification with measured combined sustained performance of 1.1 × 10 18 floating-point operations per second across multiple supercomputers, we certify 71,313 bits of entropy under this restricted adversary and additional assumptions. Our results demonstrate a step towards the practical applicability of present-day quantum computers.

computer science

Assuring and Securing Machine Learning

A short presentation highlighting using machine learning and topological data analysis to address the challenges of assuring and securing machine learning enabled systems.

Machine Learning

Capability 9.3 Assembly and Deployment

Large space systems are required for a range of operational, commercial and scientific missions objectives however, current launch vehicle capacities substantially limit the size of space systems (on-orbit or planetary). Assembly and Deployment is the process of constructing a spacecraft or system from modules which may in turn have been constructed from sub-modules in a hierarchical fashion. In-situ assembly of space exploration vehicles and systems will require a broad range of operational capabilities, including: Component transfer and storage, fluid handling, construction and assembly, test and verification. Efficient execution of these functions will require supporting infrastructure, that can: Receive, store and protect (materials, components, etc.); hold and secure; position, align and control; deploy; connect/disconnect; construct; join; assemble/disassemble; dock/undock; and mate/demate.

Dorsey, John

Payload and Components Real-Time Automated Test System (PACRATS), Data Acquisition of Leak Rate and Pressure Data Test Procedure

The purpose of this activity is to provide the Mechanical Components Test Facility (MCTF) with the capability to obtain electronic leak test and proof pressure data, Payload and Components Real-time Automated Test System (PACRATS) data acquisition software will be utilized to display real-time data. It will record leak rates and pressure/vacuum level(s) simultaneously. This added functionality will provide electronic leak test and pressure data at specified sampling frequencies. Electronically stored data will provide ES61 with increased data security, analysis, and accuracy. The tasks performed in this procedure are to verify PACRATS only, and are not intended to provide verifications for MCTF equipment.

Rinehart, Maegan L.

Understanding and Verifying Neural Networks

Deep Neural Networks (DNNs) have gained immense popularity in recent times and have widespread use in applications such as image classification, sentiment analysis, speech recognition and also in safety-critical applications such as autonomous driving. However, they suffer limitations such as lack of explainability and robustness which raise safety and security concerns in their usage. Further, the complex structure and large input spaces of DNNs act as an impediment to thorough verification and testing. The SafeDNN project at the Robust Software Engineering (RSE) group at NASA aims at exploring techniques to ensure that systems that use deep neural networks are safe, robust and interpretable. In this talk, I will be presenting our technique Prophecy that automatically infers formal properties of deep neural network models. The tool extracts patterns based on neuron activations as preconditions that imply certain desirable output properties of the model. I would be highlighting case studies that use Prophecy in obtaining explanations for network decisions, understanding correct and incorrect behavior, providing formal guarantees wrt safety and robustness, and debugging neural network models. We have applied the tool on image classification networks, neural network controllers providing turn advisories in unmanned aircrafts, regression models used for autonomous center-line tracking in aircrafts and neural network object detectors

Deep Neural Networks

Hardware Fuzzing with An Emulator

Bugs in digital logic have led to some significant security vulnerabilities. Hardware bugs are particularly troublesome since they cannot be easily patched. Additionally, if the bug is in the root of trust, all trust built upon it can be vulnerable. Traditional testing either require a deep knowledge of the system, creative attack vectors and lots of human interaction. This is not scalable as there are very few engineers that can wear the hat of a designer, a verification engineer, and a cybersecurity expert. Hardware fuzzing is a relatively new research area in dynamic hardware testing. It has proven to be an effective method for discovering bugs, unexpected behaviors, and security vulnerabilities in software. While hardware fuzzing is new to the hardware domain, it has a strong track record in software testing. Fuzzing is a testing technique that randomly mutates the input data to uncover bugs or vulnerabilities in the design. It is especially good at finding corner cases that test engineers can not envision. Another advantage over other dynamic testing techniques is that, if done well, deep knowledge of the design is not required. Additionally, fuzzing scales well. If the system is set up correctly, it can run unsupervised for weeks if necessary. In this work, we propose using hardware fuzzing to improve the input vector generation for an information flow tracking tool. To get reasonable throughput of test vectors, an emulator is targeted as the execution platform. Efficient emulator execution has some specific requirements.

42 ENGINEERING

Measuring very low radiation doses in PTFE for nuclear forensic enrichment reconstruction

Every country that has made nuclear weapons has used uranium enrichment to do so. Despite the centrality of this technology to international security, there is still no reliable physical marker of past enrichment in the open literature that can be used to perform forensic verification of historically produced weapons on gas centrifuges. We show that the extremely low radioactivity from uranium alpha emissions during enrichment leaves detectable and irreversible calorimetric signatures in the common enrichment gasket material PTFE, allowing for historical reconstruction of past enrichment activities at a sensitivity better than one weapon’s quantity of highly enriched uranium. Fast scanning calorimetry also enables the measurement of recrystallization enthalpies of sequentially microtomed slices, confirming the magnitude and the type of radiation exposure while also providing detection of tampering and a method for analyzing field samples useful for treaty verification. Furthermore, this work opens the door for common items to be turned into precise dosimeters to detect the past presence of radioactivity, nuclear materials, and related activities with high confidence.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P

Dynamic verification of very large space structures

The dynamic verification of spacecraft relies heavily on ground-based tests. These tests usually simulate flight environments or validate analytical models used in establishing design loads and in designing control algorithms. They also provide security against failures resulting from unanticipated or unmodeled hardware behavior. Future orbital antennas, space stations, and solar power systems are likely to be of sizes difficult to test using current ground test technology. In addition to size, other factors such as low natural frequencies, lightweight construction, and the presence of many structural joints, cause significant sensitivity of the test process to the earth-gravity environment. Yet, accuracy requirements on the verification process will be more stringent because of modern flexible-structure control approaches. This paper describes some of the problems and discusses research on potential solutions. The importance of an integrated ground test, analysis, and flight test program is emphasized. An ongoing research program of this type focusing on a 60-meter, deployable, truss-beam test article is described.

Hanks, B. R.

Results of an In-Field Validation Exercise in Support of Wide-Area Environmental Sampling

The National Nuclear Security Administration’s (NNSA) Office of Nonproliferation and Arms Control (NA-24) is evaluating Wide-Area Environmental Sampling (WAES) as an additional safeguards verification tool for the International Atomic Energy Agency to detect undeclared nuclear activities. The NNSA is evaluating strategies for conducting a generic WAES campaign, the cost of a WAES campaign, and the effect of technological advancements that have occurred since the last major WAES review in 1999. Until now, the NNSA effort has focused on tabletop exercises (TTXs) in which high-performance computing allows for advanced modeling and simulation efforts to be applied to the WAES question. Although the modeling and simulations used in the TTXs are extremely valuable, field campaigns are still needed to validate the assumptions that underpin the models and the modeling process itself. During a 7 week period beginning in May 2023 and ending in June 2023, which included 4 weeks of active field collections, a multilaboratory team conducted its first in-field validation exercise. Prior to the in-field exercise, abbreviated TTXs were conducted to estimate the performance of all collection systems to be used during the field test. These TTXs guided the selection of materials to be released and the placement of the collection system. Based on these determinations, materials were procured to use in the field test, and an injection/release system was designed, built, and installed at the test facility. Background samples were collected during weeks one and four, and environmental collections against active releases were conducted during weeks two and three. The goals of this validation exercise included a demonstration of (1) the ability to provide controlled releases of particulates of surrogate materials, (2) the fielding and operation of collection systems (including deposition and active air collectors), and (3) the flexibility to revise equipment and campaign plans in the field. This paper presents the results and preliminary conclusions for this initial validation test. Based on these results, subsequent field campaigns are anticipated and will include the addition of other released materials.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS

Endpoint Security Using Biometric Authentication for Secure Remote Mission Operations

We propose a flexible security authentication solution for the spacecraft end-user, which will allow the user to interact over Internet with the spacecraft, its instruments, or with the ground segment from anywhere, anytime based on the user's pre-defined set of privileges. This package includes biometrics authentication products, such as face, voice or fingerprint recognition, authentication services and procedures, such as: user registration and verification over the Internet and user database maintenance, with a configurable schema of spacecraft users' privileges. This fast and reliable user authentication mechanism will become an integral part of end-to-end ground-to-space secure Internet communications and migration from current practice to the future. All modules and services of the proposed package are commercially available and built to the NIST BioAPI standard, which facilitates "pluggability" and interoperability.

Donohue, John T.

Foreign Entity of Concern Requirements in the One Big Beautiful Bill Act

The One Big Beautiful Bill Act (OBBB), enacted July 4, 2025, makes billions of dollars in federal energy tax credits conditional on supply chain independence from China and other foreign entities of concern. The OBBB simultaneously creates powerful economic incentives to reshore energy supply chains to the United States and allied nations. Through such incentives, the OBBB elevates digital assurance and supply chain verification from voluntary best practices into critical capabilities for demonstrating tax credit eligibility. The OBBB uses tax credit eligibility requirements to simultaneously address national security concerns regarding foreign supply chain dependencies and incentivize domestic energy manufacturing. This brief details how organizations should operationalize these requirements through baseline compliance audits, interim documentation systems, supply chain diversification strategies, and long-term institutional integration of digital assurance capabilities that turn compliance burdens into competitive advantages

29 - ENERGY PLANNING, POLICY AND ECONOMY