Search NASA⌕ Search

SEARCH · Search NASA

Results for “Secure by Design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 109 records · Page 6

Ares V: Game Changer for National Security Launch

NASA is designing the Ares V cargo launch vehicle to vastly expand exploration of the Moon begun in the Apollo program and enable the exploration of Mars and beyond. As the largest launcher in history, Ares V also represents a national asset offering unprecedented opportunities for new science, national security, and commercial missions of unmatched size and scope. The Ares V is the heavy-lift component of NASA's dual-launch architecture that will replace the current space shuttle fleet, complete the International Space Station, and establish a permanent human presence on the Moon as a stepping-stone to destinations beyond. During extensive independent and internal architecture and vehicle trade studies as part of the Exploration Systems Architecture Study (ESAS), NASA selected the Ares I crew launch vehicle and the Ares V to support future exploration. The smaller Ares I will launch the Orion crew exploration vehicle with four to six astronauts into orbit. The Ares V is designed to carry the Altair lunar lander into orbit, rendezvous with Orion, and send the mated spacecraft toward lunar orbit. The Ares V will be the largest and most powerful launch vehicle in history, providing unprecedented payload mass and volume to establish a permanent lunar outpost and explore significantly more of the lunar surface than was done during the Apollo missions. The Ares V consists of a Core Stage, two Reusable Solid Rocket Boosters (RSRBs), Earth Departure Stage (EDS), and a payload shroud. For lunar missions, the shroud would cover the Lunar Surface Access Module (LSAM). The Ares V Core Stage is 33 feet in diameter and 212 feet in length, making it the largest rocket stage ever built. It is the same diameter as the Saturn V first stage, the S-IC. However, its length is about the same as the combined length of the Saturn V first and second stages. The Core Stage uses a cluster of five Pratt & Whitney Rocketdyne RS-68B rocket engines, each supplying about 700,000 pounds of thrust. Its propellants are liquid hydrogen and liquid oxygen. The two solid rocket boosters provide about 3.5 million pounds of thrust at liftoff. These 5.5-segment boosters are derived from the 4-segment boosters now used on the Space Shuttle, and are similar to those used in the Ares I first stage. The EDS is powered by one J-2X engine. The J-2X, which has roughly 294,000 pounds of thrust, also powers the Ares I Upper Stage. It is derived from the J-2 that powered the Saturn V second and third stages. The EDS performs two functions. Its initial suborbital burns will place the lunar lander into a stable Earth orbit. After the Orion crew vehicle, launched separately on an Ares I, docks with the lander/EDS stack, EDS will ignite a second time to put the combined 65-metric ton vehicle into a lunar transfer orbit. When it stands on the launch pad at Kennedy Space Center late in the next decade, the Ares V stack will be approximately 381 feet tall and have a gross liftoff mass of 8.1 million pounds. The current point-of-departure design exceeds Saturn V s mass capability by approximately 40 percent. Using the current payload shroud design, Ares V can carry 315,000 pounds to 29-degree low Earth orbit (LEO) or 77,000 pounds to a geosynchronous orbit. Another unique aspect of the Ares V is the 33-foot-diameter payload shroud, which encloses approximately 30,400 cubic feet of usable volume. A larger hypothetical shroud for encapsulating larger payloads has been studied. While Ares V makes possible larger payload masses and volumes, it may alternately make possible more cost-effective mission design if the relevant payload communities are willing to consider an alternative to the existing approach that has driven them to employ complexity to solve current launch vehicle mass and volume constraints. By using Ares V s mass and volume capabilities as margin, payload designers stand to reduce development risk and cost. Significant progress has been made on the Ares V to support a plaed fiscal 2011 authority-to-proceed (ATP) milestone. The Ares V team is actively reaching out to external organizations during this early concept phase to ensure that the Ares V vehicle can be leveraged for national security, science, and commercial development needs. This presentation will discuss Ares V vehicle configuration, the path to the current concept, accomplishments to date, and potential payload utilization opportunities.

Sumrall, Phil↗

Advanced Utilization of the Payload Executive Processor (PEP) Ethernet Port to Support JSL Based Payloads

Increased interest by Payload Developers in utilization of the Joint Station LAN (Local Area Network) (JSL) for command and data transactions has driven the investigation of providing bi-directional Ethernet communication with PEP (Payload Executive Processor). Ethernet-only payload developers are interested in taking advantage of the services provided by PEP. Enabling Ethernet communications within PEP requires more than just turning on the hardware. PEP contains no Operating System (OS) or Ethernet stack so it does not inherit any built in functionality for Ethernet support. Both hardware drivers and application software must be developed from scratch. In the absence of an OS (Operating System) the design must address security issues in terms of access and data transferred, i.e. blocking unauthorized users and preventing denial of service. Developing a design to process Ethernet data within the existing real-time constraints of PEP requires a few compromises: data rates, supported protocols, custom packet format and limited client connections to name a few. Integration of the light weight internet protocol (LwIP). Ethernet stack provides a customizable solution for the embedded real-time environment. As utilization of the JSL increases, the successful implementation of an Ethernet interface enhances the utilization of PEP, and provides a new path for future Ethernet-only payloads to gain access to around the clock command and data services.

Guyette, Greg↗

Proposed Classifications of Remote Operations for Nuclear Reactors Based on Physical and Cybersecurity Considerations

The incorporation of remote operations into reactor operations is a topic of high interest among advanced and small modular reactor (A/SMR) vendors, with some considering it essential to the success of their business models. However, remote operations are a concept novel to the nuclear industry. While various technical aspects of remote operations have been explored, a significant gap remains in understanding the security implications of integrating remote operations into reactor designs, particularly concerning the security requirements for remote-operations facilities and infrastructure. This report aims to address this gap by first defining classes of remote operation based on the extent of remote access to reactor control systems and grounded in the existing regulatory framework with compatible terminology. Secondly, the report outlines the physical and cybersecurity requirements applicable to remote-operations facilities and infrastructure at each defined class. These requirements are based on existing licensing frameworks provided by 10 Code of Federal Regulations (CFR) Part 50 and 10 CFR Part 52, as well as the upcoming A/SMR licensing framework in the proposed Part 53. The assessment focuses specifically on security regulations, such as 10 CFR Part 73, which includes provisions for both cybersecurity (§ 73.54) and physical security (§ 73.55). This report proposes five classes of remote reactor operations. Class 1 involves remote monitoring only, with no control over reactor systems. Class 2 allows for the remote issuance of allowlisted commands to the reactor facility. Class 3 extends control to non-safety-significant, non-safety-related, or not important to safety systems and equipment. Class 4 permits remote control of safety-significant systems. Finally, Class 5 allows remote control of safety-related systems. It is important to note that these classes were defined purely with functionality in mind, without considering the practicality or feasibility of implementation for each class under current or upcoming regulatory guidance. The intention behind this approach is to enable an assessment of which security requirements apply to each class, allowing readers to evaluate the implementation possibilities for their specific use cases. Following the definition of remote-operation classes, the report assesses the specific physical and cybersecurity requirements applicable to the remote-operations facility and infrastructure within each defined class. This includes defining the types and locations of operators that are possible at each class of operation and, based on operator type and location, as well as functionality within each class, outlining the physical and cybersecurity requirements. By detailing the security requirements by class, the report provides readers with the information needed to determine the type of security program they may need to implement for their desired concept of operation. The next contribution of this report was to assess the practicality of implementing each proposed class of remote operations based upon the security requirement assessment. In short, three of the five proposed remote-operation classes were found to possibly have a practical path forward to implementation under the U.S. regulatory framework. Class 1 remote operations are currently in use in the U.S. while Class 2 and 3 remote operations may be logistically possible to implement under the U.S. regulatory framework. The final two Classes, 4 and 5, would likely be logistically difficult, if not infeasible to implement within the current U.S. physical- and cybersecurity regulatory framework. Given the results of the feasibility assessment, an example architecture is proposed for both Class 2, remote allowlisted commands, and Class 3, remote control of non-safety systems as well as security implication assessments of each architecture. These example implementations are not meant to be prescriptive in terms of how Class 2 or Class 3 remote operations should be deployed; instead, they are intended to be informative to stakeholders on how Class 2 or Class 3 could potentially be applied in order to inform their system design. An example architecture for Class 1 remote monitoring was not provided as Class 1 in already in use in U.S. nuclear operations. Example architectures for Class 4 and Class 5 were not provided due to their assessment of being likely infeasible to implement. The final contribution is an assessment of the physical- and cybersecurity implications of introducing autonomous operations into an A/SMR. What was found was that the security implications can be separated into two cases. Autonomous operations supported by SSCs located only at the reactor site, and autonomous operations supported by SSCs outside of the reactor site. For the first case, the introduction of autonomous systems will likely not change the facility’s requirement to comply with existing cyber and physical security regulation

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Feasibility study of an Integrated Program for Aerospace vehicle Design (IPAD). Volume 4: IPAD system design

The computing system design of IPAD is described and the requirements which form the basis for the system design are discussed. The system is presented in terms of a functional design description and technical design specifications. The functional design specifications give the detailed description of the system design using top-down structured programming methodology. Human behavioral characteristics, which specify the system design at the user interface, security considerations, and standards for system design, implementation, and maintenance are also part of the technical design specifications. Detailed specifications of the two most common computing system types in use by the major aerospace companies which could support the IPAD system design are presented. The report of a study to investigate migration of IPAD software between the two candidate 3rd generation host computing systems and from these systems to a 4th generation system is included.

Goldfarb, W.↗

Enabling Secure and Resilient XFC: A Software/Hardware-Security Co-Design Approach

Extremely fast charging (XFC) has the potential to reduce the charging time of battery electric vehicles (BEV) to be equivalent to the filling time of internal combustion engine vehicles (ICEV), thus eliminating one of the few advantages ICEV still poses for light- and heavy-duty vehicles. Enabling XFC will, however, require coordination and cooperation between the grid, charging stations, and the vehicles themselves, which leads to an inevitable increase in the attack surface for all systems combined. In securing the overall system, we must not only embrace traditional cybersecurity, which is chiefly concerned with communications and the operation of digital systems, but also cyber-physical systems security as the proper operation of XFC is critically dependent on systems’ abilities to know about (sense) and interact with (actuate) the physical world. The project team consists of academic and industry researchers with backgrounds in cybersecurity, cyber-physical systems security, learning in adversarial environments, transportation security, grid security and resilience, wireless power transfer, converter design, and battery management systems.

33 ADVANCED PROPULSION SYSTEMS↗

Mission planning for Shuttle Imaging Radar-C (SIR-C) with a real-time interactive planning software

The Shuttle Imaging Radar-C (SIR-C) mission will operate from the payload bay of the space shuttle for 8 days, gathering Synthetic Aperture Radar (SAR) data over specific sites on the Earth. The short duration of the mission and the requirement for realtime planning offer challenges in mission planning and in the design of the Planning and Analysis Subsystem (PAS). The PAS generates shuttle ephemerides and mission planning data and provides an interactive real-time tool for quick mission replanning. It offers a multi-user and multiprocessing environment, and it is able to keep multiple versions of the mission timeline data while maintaining data integrity and security. Its flexible design allows one software to provide different menu options based on the user's operational function, and makes it easy to tailor the software for other Earth orbiting missions.

Potts, Su K.↗

Distribution System Behind-the-Meter DERs: Estimation, Uncertainty Quantification, and Control

This paper summarizes the three-year technical activities of the IEEE Task Force (TF) on behind-the-meter (BTM) distributed energy resources (DERs): estimation, uncertainty quantification, and control. The potential grid services from BTM DERs are discussed in detail. The paper also reviews the state-of-the-art for BTM DERs visibility, uncertainty quantification, and, optimization and control. Furthermore, different aspects of the market structures associated with BTM DERs are covered, including emerging market and business models. Finally, needs and recommendations are provided for additional areas such as system protection, computing capabilities, algorithm development, market structure design, cyberinfrastructure and security, and hardware and software developments.

behind-the-meter↗

System security in the space flight operations center

The Space Flight Operations Center is a networked system of workstation-class computers that will provide ground support for NASA's next generation of deep-space missions. The author recounts the development of the SFOC system security policy and discusses the various management and technology issues involved. Particular attention is given to risk assessment, security plan development, security implications of design requirements, automatic safeguards, and procedural safeguards.

Wagner, David A.↗

DIstributed VIRtual System (DIVIRS) Project

The development of Prospero moved from the University of Washington to ISI and several new versions of the software were released from ISI during the contract period. Changes in the first release from ISI included bug fixes and extensions to support the needs of specific users. Among these changes was a new option to directory queries that allows attributes to be returned for all files in a directory together with the directory listing. This change greatly improves the performance of their server and reduces the number of packets sent across their trans-pacific connection to the rest of the internet. Several new access method were added to the Prospero file method. The Prospero Data Access Protocol was designed, to support secure retrieval of data from systems running Prospero.

Schorr, Herbert↗

NASA Technology Benefits Orthotics

Engineers at NASA's Marshall Space Flight Center (MSFC) in Huntsville, Alabama have designed a knee brace to aid in the rehabilitation of medical patients. The device, called the Selectively Lockable Knee Brace, was designed for knee injury and stroke patients but may potentially serve in many more patient applications. Individuals with sports related injuries, spinal cord injuries and birth defects, such as spina bifida, may also benefit from the device. The Selectively Lockable Knee Brace is designed to provide secure support to the patient when weight is applied to the leg; however; when the leg is not supporting weight, the device allows free motion of the knee joint. Braces currently on the market lock the knee in a rigid, straight or bent position, or by manually pulling a pin, allow continuous free joint motion.

Myers, Neill↗

Using Ontologies to Formalize Services Specifications in Multi-Agent Systems

One key issue in multi-agent systems (MAS) is their ability to interact and exchange information autonomously across applications. To secure agent interoperability, designers must rely on a communication protocol that allows software agents to exchange meaningful information. In this paper we propose using ontologies as such communication protocol. Ontologies capture the semantics of the operations and services provided by agents, allowing interoperability and information exchange in a MAS. Ontologies are a formal, machine processable, representation that allows to capture the semantics of a domain and, to derive meaningful information by way of logical inference. In our proposal we use a formal knowledge representation language (OWL) that translates into Description Logics (a subset of first order logic), thus eliminating ambiguities and providing a solid base for machine based inference. The main contribution of this approach is to make the requirements explicit, centralize the specification in a single document (the ontology itself), at the same that it provides a formal, unambiguous representation that can be processed by automated inference machines.

Breitman, Karin Koogan↗

FL‐ADS: Federated learning anomaly detection system for distributed energy resource networks

Abstract With the ongoing development of Distributed Energy Resources (DER) communication networks, the imperative for strong cybersecurity and data privacy safeguards is increasingly evident. DER networks, which rely on protocols such as Distributed Network Protocol 3 and Modbus, are susceptible to cyberattacks such as data integrity breaches and denial of service due to their inherent security vulnerabilities. This paper introduces an innovative Federated Learning (FL)‐based anomaly detection system designed to enhance the security of DER networks while preserving data privacy. Our models leverage Vertical and Horizontal Federated Learning to enable collaborative learning while preserving data privacy, exchanging only non‐sensitive information, such as model parameters, and maintaining the privacy of DER clients' raw data. The effectiveness of the models is demonstrated through its evaluation on datasets representative of real‐world DER scenarios, showcasing significant improvements in accuracy and F1‐score across all clients compared to the traditional baseline model. Additionally, this work demonstrates a consistent reduction in loss function over multiple FL rounds, further validating its efficacy and offering a robust solution that balances effective anomaly detection with stringent data privacy needs.

Purohit, Shaurya [Iowa State University Ames Iowa ↗

A model of security monitoring

A model of security monitoring is presented that distinguishes between two types of logging and auditing. Implications for the design and use of security monitoring mechanisms are drawn from this model. The usefulness of the model is then demonstrated by analyzing several different monitoring mechanisms.

Bishop, Matt↗

A model of security monitoring

A model of security monitoring is presented that distinguishes between two types of logging and auditing. Implications for the design and use of security monitoring mechanisms are drawn from this model. The usefulness of the model is then demonstrated by analyzing several different monitoring mechanisms.

Bishop, Matt↗

Analyzing the security of an existing computer system

Most work concerning secure computer systems has dealt with the design, verification, and implementation of provably secure computer systems, or has explored ways of making existing computer systems more secure. The problem of locating security holes in existing systems has received considerably less attention; methods generally rely on thought experiments as a critical step in the procedure. The difficulty is that such experiments require that a large amount of information be available in a format that makes correlating the details of various programs straightforward. This paper describes a method of providing such a basis for the thought experiment by writing a special manual for parts of the operating system, system programs, and library subroutines.

Bishop, M.↗

The Impact of Cultural Values and Organizational Processes on Nuclear Security Operations

Human performance is a pivotal factor in the design, testing, maintenance, and operation of security systems. The effectiveness of these systems relies not only on the capabilities, limitations, motives, and attitudes of the individuals involved, but also on the quality of training, instructional content, and evaluation methods provided. To uphold security standards, seamless integration between technologies and operators necessitates reliable human input. In security operations, human errors, often attributed to blame, sanctions, low motivation, individual accountability, or complacency, are primary causes of system failures. Complacency, characterized by a false sense of security, reflects a lack of awareness of potential threats and is a significant contributing factor to lapses in security. Security incidents arise from various factors, many extend beyond individual control, highlighting the need for a holistic approach to human performance that integrates organizational processes and team collaboration. Historically, errors have been attributed to individual moral or cognitive failures. However, insights from Operational Experiences (OEs) suggest that organizational processes weakness and deficiencies in nuclear cultural values contribute more significantly to security failures than individual mistakes. This paper consolidates lessons learned from diverse international nuclear security cultures and aims to highlight the importance of security culture in shaping global perspectives on nuclear security. It underscores the role of cultural values in shaping nuclear security practices and enhancing the resilience of security systems in the nuclear sector.

Zineddin, Dr. Z. [ORNL] (ORCID:0009000848740725)↗

Requirements for a network storage service

Sandia National Laboratories provides a high performance classified computer network as a core capability in support of its mission of nuclear weapons design and engineering, physical sciences research, and energy research and development. The network, locally known as the Internal Secure Network (ISN), was designed in 1989 and comprises multiple distributed local area networks (LAN's) residing in Albuquerque, New Mexico and Livermore, California. The TCP/IP protocol suite is used for inner-node communications. Scientific workstations and mid-range computers, running UNIX-based operating systems, compose most LAN's. One LAN, operated by the Sandia Corporate Computing Directorate, is a general purpose resource providing a supercomputer and a file server to the entire ISN. The current file server on the supercomputer LAN is an implementation of the Common File System (CFS) developed by Los Alamos National Laboratory. Subsequent to the design of the ISN, Sandia reviewed its mass storage requirements and chose to enter into a competitive procurement to replace the existing file server with one more adaptable to a UNIX/TCP/IP environment. The requirements study for the network was the starting point for the requirements study for the new file server. The file server is called the Network Storage Services (NSS) and is requirements are described in this paper. The next section gives an application or functional description of the NSS. The final section adds performance, capacity, and access constraints to the requirements.

Kelly, Suzanne M.↗

Cyber-Informed Engineering Adoption in University Engineering Programs: An Overview of CIE Integration Successes at Nine U.S. Educational Institutions

This report examines the adoption of Cyber-Informed Engineering (CIE) in university engineering programs, driven by the need to protect critical energy infrastructure from adversarial threats. CIE equips current and future engineers and technicians with the necessary mindset, skills, and competencies to enhance the resilience of engineered systems against cyber attacks. This report highlights nine academic partners who are incorporating CIE into their curricula through various approaches, including lectures, courses, and certificates.

42 ENGINEERING↗