Search NASA⌕ Search

SEARCH · Search NASA

Results for “Secure by Design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

Genomics and Proteomics Based Security Protocols for Secure Network Architectures

A hardware design that integrates live and algorithmic inhabitants to produce patterns of gene expression in vivo and in silico Protocols and algorithms based upon the processes of regulation of gene expression to produce cryptographic representations of genes, RNA, proteins, and gene expression to perform authentication and confidentiality functions for computers and networks. A network concept of operations integrating all of the above into existing legacy networks.

Security Genomics↗

R2U2: Monitoring and Diagnosis of Security Threats for Unmanned Aerial Systems

We present R2U2, a novel framework for runtime monitoring of security properties and diagnosing of security threats on-board Unmanned Aerial Systems (UAS). R2U2, implemented in FPGA hardware, is a real-time, REALIZABLE, RESPONSIVE, UNOBTRUSIVE Unit for security threat detection. R2U2 is designed to continuously monitor inputs from the GPS and the ground control station, sensor readings, actuator outputs, and flight software status. By simultaneously monitoring and performing statistical reasoning, attack patterns and post-attack discrepancies in the UAS behavior can be detected. R2U2 uses runtime observer pairs for linear and metric temporal logics for property monitoring and Bayesian networks for diagnosis of security threats. We discuss the design and implementation that now enables R2U2 to handle security threats and present simulation results of several attack scenarios on the NASA DragonEye UAS.

Formal Methods↗

Securing mechanism for the deployable column of the Hoop/Column antenna

The Column Longeron Latch (CLL) was designed and developed as the securing mechanism for the deployable, telescoping column of the Hoop/Column antenna. The column is an open lattice structure with three longerons as the principal load-bearing members. It is divided into telescoping sections that are deployed after the antenna is place in Earth orbit. The CLL provides a means to automatically lock the longeron sections into position during deployment as well as a means of unlocking the sections when the antenna is to be restowed. The CLL is a four bar linkage mechanism using the over center principle for locking. It utilizes the relative movement of the longeron sections to activate the mechanism during antenna deployment and restowing. The CLL design is one of the first mechanisms developed to meet the restowing requirements of spacecraft which will utilize the STS retrieval capability.

Ahl, E. L., Jr.↗

Integrating Safety, Security, and Nuclear Operations for Advanced Reactors

The traditional separation between safety, security, and operations teams has created significant barriers to achieving optimal outcomes. When security considerations are introduced late in the design process, they often conflict with already-established architectural, operational, or engineering parameters. Retrofitting security measures can lead to increased costs, schedule delays, and compromises in security effectiveness. For instance, the need to retrofit physical barriers or surveillance systems often results in trade-offs that could have been avoided with earlier input from security professionals. Delayed integration can also affect regulatory processes and result in licensing delays. Security reviews conducted at later stages frequently identify gaps that necessitate significant redesign efforts, impacting not only scope, schedule, and budget, but also adding risk and lowering stakeholder confidence in the project. This paper aims to address these challenges by identifying practical opportunities for integrating security considerations seamlessly with design and operations teams throughout the entire lifecycle of nuclear facilities—from conceptual design to commissioning and beyond. The research emphasizes the value of early and continuous collaboration among stakeholders to ensure that security measures are robust, operationally effective, and cost-efficient. By examining case studies, analyzing past incidents, and leveraging best practices from other high-security industries, this study highlights actionable strategies for bridging the gap between safety, security, and operations teams.

Zineddin, Dr. Z. [ORNL] (ORCID:0009000848740725)↗

Integrating Cyber-Informed Engineering into Enterprise Risk Management

This document supports the application of Cyber-Informed Engineering (CIE) within the context of Enterprise Risk Management (ERM) to enhance cyber-resilience. It highlights that many critical infrastructure organizations use ERM to manage business risks and emphasizes the importance of evaluating critical systems and assets. The proposed approach can be adopted independently of formal ERM processes and offers a starting point for integrating CIE alongside existing or new ERM practices. Both CIE and ERM are iterative, and their alignment fosters continuous improvement and supports the engineering and operations cultures of an organization.

42 ENGINEERING↗

NASA Aeronautics Research Mission Directorate System Security Engineering Approaches

System security engineering (SSE) is a set of formal engineering methods and is considered a subset of systems engineering. It is a relatively new development in systems engineering with the initial NIST (National Institute of Standards) standard published in November of 2016 with updates in 2018, and 2022. The guiding principles in our methodology are based in NIST Special Publication 800-160 Vol. 1 “Systems Security Engineering: Considerations For A Multidisciplinary Approach In The Engineering Of Trustworthy Secure Systems” and integrate methodologies from common IT (Information Technology) threat modeling approaches utilizing MBSE (Model-Based Systems Engineering). The presentation will discuss how our teams utilize SSE and MBSE (Model-Based Systems Engineering) to develop secure architectures for systems under development in our NASA aeronautics research environment. This includes the activities to develop Protection Needs (PN) that, in turn result in security requirements in the design context and policies for the future state operational context for system protection. The process of applying SSE to analyze project architectures and ConOps (Concept of Operations) is intended to ensure the transferred research is both secure and securable in a “real-world” setting.

Systems Security Engineering↗

Security System Software

C Language Integration Production System (CLIPS), a NASA-developed expert systems program, has enabled a security systems manufacturer to design a new generation of hardware. C.CURESystem 1 Plus, manufactured by Software House, is a software based system that is used with a variety of access control hardware at installations around the world. Users can manage large amounts of information, solve unique security problems and control entry and time scheduling. CLIPS acts as an information management tool when accessed by C.CURESystem 1 Plus. It asks questions about the hardware and when given the answer, recommends possible quick solutions by non-expert persons.

Source record↗

Safe Grid

The biggest users of GRID technologies came from the science and technology communities. These consist of government, industry and academia (national and international). The NASA GRID is moving into a higher technology readiness level (TRL) today; and as a joint effort among these leaders within government, academia, and industry, the NASA GRID plans to extend availability to enable scientists and engineers across these geographical boundaries collaborate to solve important problems facing the world in the 21 st century. In order to enable NASA programs and missions to use IPG resources for program and mission design, the IPG capabilities needs to be accessible from inside the NASA center networks. However, because different NASA centers maintain different security domains, the GRID penetration across different firewalls is a concern for center security people. This is the reason why some IPG resources are been separated from the NASA center network. Also, because of the center network security and ITAR concerns, the NASA IPG resource owner may not have full control over who can access remotely from outside the NASA center. In order to obtain organizational approval for secured remote access, the IPG infrastructure needs to be adapted to work with the NASA business process. Improvements need to be made before the IPG can be used for NASA program and mission development. The Secured Advanced Federated Environment (SAFE) technology is designed to provide federated security across NASA center and NASA partner's security domains. Instead of one giant center firewall which can be difficult to modify for different GRID applications, the SAFE "micro security domain" provide large number of professionally managed "micro firewalls" that can allow NASA centers to accept remote IPG access without the worry of damaging other center resources. The SAFE policy-driven capability-based federated security mechanism can enable joint organizational and resource owner approved remote access from outside of NASA centers. A SAFE enabled IPG can enable IPG capabilities to be available to NASA mission design teams across different NASA center and partner company firewalls. This paper will first discuss some of the potential security issues for IPG to work across NASA center firewalls. We will then present the SAFE federated security model. Finally we will present the concept of the architecture of a SAFE enabled IPG and how it can benefit NASA mission development.

Chow, Edward T.↗

NASA's Photon-Counting SLR2000 Satellite Laser Ranging System: Progress and Applications

NASA's new unmanned SLR2000 system is designed to track, with millimeter precision and using single photon returns, a constellation of roughly 24 retroreflector-equipped satellites, which range in altitude from about 300 km to 20,000 km. Totally autonomous operation and a common engineering configuration are expected to greatly reduce station operations costs relative to NASA's current manned systems. The system has also been designed with a goal of significantly lowering replication costs. All of the prototype components and subsystems have been completed and tested and have substantially met the original specifications. The prototype system is presently undergoing final integration and testing in a dedicated shelter with an azimuth tracking dome synchronized to the optical tracking mount. The facility also features a number of security features such as security cameras and sensors designed to detect power or thermal control problems or entry by unauthorized personnel. Field tests are in progress. The present paper provides an overview of the various subsystems and test results to date. The meteorological subsystem, which has operated successfully in the field for almost three years, consists of several sensors which measure: (1) pressure, temperature, and relative humidity; (2) wind speed and direction; (3) ground visibility and precipitation; and (4) local cloud cover as a function of station azimuth and elevation (day and night). A "pseudo-operator" software program interprets the sensor readings and modifies satellite tracking priorities based on local meteorological conditions.

Degnan, John J.↗

Battery Energy Storage Systems Report

Battery energy storage systems (BESS) are a critical component of grid reliability and resilience today, providing rapid response capabilities while enabling grid modernization and capacity expansion across the United States. As utilities, communities, and customers prepare to deploy significant BESS capacity over the next several years, the United States has an opportunity to build security into battery system design and deployments. This report provides a framework for assessing the current dominance of foreign-manufactured components in the supply chains for BESS, inverter-based resources, and transformers. It offers high-impact, actionable solutions to service partners, industry, and government to address supply chain risks for currently installed, in design, and future deployments.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

International Nuclear Security Nuclear Material Accounting and Control Instructions for Use and Supplementary Documentation

This document describes the use of exercise kits (called NMAC Kits) developed to support training and technical engagements sponsored by DOE/NNSA Office of Nuclear Security (INS) in the use of nuclear material accounting and control (NMAC) methodologies in support of nuclear security. INS has previously used other similar kits that were originally designed to support NMAC training for international safeguards purposes. These new kits are specifically designed to be used in nuclear security training and emphasis the role NMAC plays in nuclear security as well as security against the insider threat. Planning for the development of these kits is described in LA-UR-24-30063, FY24 NMAC Kits Upgrade and served as the initial framework for the development of the new NMAC Kit material in FY25.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Laboratory Tool

Veterans Administration medical researchers, along with Langley Research Center are investigating possibility that peritoneal membrane (lining of abdominal cavity) can absorb nutrients and thus provide alternative route for nutrition when intestinal function is impaired. Apparatus (cake box design) consists of octagonal chamber with eight smaller chambers attached and secured by O-ring seals. Design is simple, interchangeable, and time controllable.

Source record↗

Development of a Helical Closure for Radioactive Material Shipping Packages

The Savannah River National Laboratory (SRNL) Packaging Technology group proposed a closure design for the outer packaging of a prototype Type B shipping package being developed for the Department of Energy (DOE). The closure design provides an efficient means of securing the containment vessel (CV) within the radioactive material packaging. This design has a simplified operation, requires less components, and less maintenance when compared to current radioactive material package closure methods. This paper will review and discuss the materials, designs, processes, and testing activities that were considered and pursued in the development of the novel closure for the outer packaging of new radioactive material shipping packages.

Housley, William M. [Savannah River National Labor↗

CMIP6-based Multi-model Streamflow Projections over the Conterminous US, Version 1.1

This dataset presents an ensemble of streamflow projections covering the conterminous United States (CONUS), developed to support the SECURE Water Act Section 9505 Assessment for the US Department of Energy (DOE) Water Power Technologies Office (WPTO). Multiple Coupled Models Intercomparison Project phase 6 (CMIP6) Global Climate Models (GCMs) were downscaled using either statistical (DBCCA) or dynamical (RegCM) downscaling methods, based on two meteorological reference datasets (Daymet and Livneh). Subsequently, the downscaled precipitation, temperature, and wind speed data were used to drive two calibrated hydrologic models (VIC and PRMS), with total runoff routed through the Routing Application for Parallel computatIon of Discharge (RAPID) routing model, producing an ensemble of streamflow projections across 2.7 million NHDPlusV2 stream reaches across the CONUS. Each ensemble member covers the 1980-2019 baseline and 2020-2059 near-future periods under the high-end (SSP585) emission scenario. Additionally, using only DBCCA and Daymet, the projections extend to the 2060-2099 far-future period and encompass three additional emission scenarios (SSP370, SSP245, and SSP126). This dataset is designed to support the SECURE Water Act Section 9505 Assessment for the US Department of Energy (DOE) Water Power Technologies Office (WPTO). For further details, refer to Kao et al. (2022), Rastogi et al. (2022), and Ghimire et al. (2023).

13 HYDRO ENERGY↗

Real-World Cyber Security Demonstration for Networked Electric Drives

In this article, we present the design and implementation of a cyber-physical security testbed for networked electric drive systems, aimed at conducting real-world security demonstrations. To our knowledge, this is one of the first security testbeds for networked electric drives, seamlessly integrating the domains of power electronics and computer science, and cybersecurity. By doing so, the testbed offers a comprehensive platform to explore and understand the intricate and often complex interactions between cyber and physical systems. The core of our testbed consists of four electric machine drives, meticulously configured to emulate small-scale but realistic information technology (IT) and operational technology (OT) networks. This setup both provides a controlled environment for simulating a wide array of cyber-attacks, and mirrors potential real-world attack scenarios with a high degree of fidelity. The testbed serves as an invaluable resource for the study of cyber-physical security, offering a practical and dynamic platform for testing and validating cybersecurity measures in the context of networked electric drive systems. As a concrete example of the testbed's capabilities, we have developed and implemented a Python-based script designed to execute step-stone attacks over a wireless local area network (WLAN). This script leverages a sequence of target IP addresses, simulating a real-world attack vector that could be exploited by adversaries. To counteract such threats, we demonstrate the efficacy of our developed cyber-attack detection algorithms, which are integral to our testbed's security framework. Furthermore, the testbed incorporates a real-time visualization system using InfluxDB and Grafana, providing a dynamic and interactive representation of networked electric drives and their associated security monitoring mechanisms. This visualization component not only enhances the testbed's usability but also offers insightful, real-time data for researchers and practitioners, thereby facilitating a deeper understanding of cyber-physical security dynamics in networked electric drive systems.

24 POWER TRANSMISSION AND DISTRIBUTION↗

High-Altitude ADS-B/GPS LPV Flight Tests on a NASA ER-2 Research Airplane

The research presented in this paper describes the conceptual design of a system architecture that integrates Automatic Dependent Surveillance-Broadcast (ADS-B) and Global Positioning System (GPS) Localizer Performance Vertical (LPV) guidance technology onto a unique high-altitude research airplane: a United States Air Force (USAF) / Lockheed Martin (Bethesda, Maryland) Aeronautics U-2S airplane. The design features modern display capabilities to provide air-to-air surveillance and precision navigation, to adhere to Federal Aviation Administration (FAA) certification standards for operations in upper Class E airspace. The National Aeronautics and Space Administration (NASA) variant of the U-2S, now called the Earth Resources (ER-2) airplane, remains unrivaled in the art of sustained high-altitude flight for scientific expeditions. Capable of routinely cruising above flight level (FL) 650 that had been considered, at inception, the domain of only the most elite experimental research aircraft types. Nicknamed the Dragon Lady, this U-2S research testbed is still one of the most advanced aircraft in the world. The exceptional military design of the vehicle, security guidelines, and the performance envelope of the ER-2 posed unique challenges to the integration of modern civilian avionics. ADS-B epitomizes the next generation of surveillance technology, incorporating both air and ground aspects. ADS-B provides air traffic control (ATC) with a more accurate picture of the three-dimensional positioning of aircraft in various phases of flight, including en route, terminal, approach, and ground operations. The airborne surveillance system broadcasts its identification, position, altitude, velocity, and other information. GPS LPV represents a significant advancement in aviation technology, emphasizing the pivotal role that GPS and Performance-Based Navigation concepts will play in the foreseeable future. This technology represents a shift from sensor-based navigation to performance-based navigation, allowing for more flexible and efficient use of airspace. This research described herein is structured as follows: Section II, “Systems Background,” provides a systems background and description of an ADS-B and GPS LPV system equipped on the high-altitude ER-2 research airplane to satisfy the FAA airworthiness requirements for high-altitude flight operations. Section III, “Flight Test System,” describes the flight-test airplane systems. Section IV, “Analysis of GPS SBAS, Safety, and Ground Tests,” provides an overview of the GPS Satellite-Based Augmentation System (SBAS) and an analysis of the GPS LPV metrics, safety, and ground tests. Section V, “High-Altitude Flight Tests,” describes the high-altitude flight tests, including 3 flight-test results, analysis, human factors, and lessons learned. Section VI, the conclusion, draws insights from the lessons learned, discusses the design challenges associated with ADS-B and GPS LPV, and showcases the paramount significance of these pivotal technologies in aircraft surveillance and navigation.

Ricardo A. Arteaga↗

Digital Droplet PCR and Mesocosm-Based Methods to Evaluate Biocontainment Strategies in a Native Soil Ecosystem

Genetically modified industrial production microbes and their associated bioproducts have emerged as an integral component of a sustainable bioeconomy. However, the rapid development of these innovative technologies raises biosecurity concerns, namely, the risk of environmental escape. Thus, the realization of a bioeconomy hinges not only on the development and deployment of microbial production hosts, but also on the development of secure biosystems and biocontainment designs. Current laboratory-based biocontainment testing systems do not accurately reflect the complexities found in natural environments, necessitating an environmentally relevant analysis pipeline that allows for the detection of rare escapees within a complex soil microbiome and differentiation between closely related strains. To this end, we have developed an approach that utilizes soil mesocosms and integrated digital droplet PCR (ddPCR) system to evaluate the efficacy of novel biocontainment strategies. We demonstrate the utility of this approach by modeling contamination with industrial microbial chasses versus their biocontained counterparts. Here we demonstrate the broad utility of this system by highlighting findings from strains of Saccharomyces cerevisiae that are contained with an inducible toxin anti-toxin system, strains of Synechocystis sp. PCC 6803 contained via gene knockout or toxin anti-toxin system, and strains of Escherichia coli that are contained via genomic recoding. We also show that ddPCR can be used to detect gene copies from E. coli equal to those counted by traditional spot plating assays. The resultant data demonstrates that this system has broad utility across diverse microbial chassis and biocontainment strategies and enables researchers to track the fate of our contaminating microbe with high sensitivity in the soil. The findings presented here support the use of this mesocosm-based approach to assess the environmental impact of industrial microbes and to validate biocontainment strategies.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH↗

Validating automated resonance evaluation with synthetic data

The integrity and precision of nuclear data are crucial for a broad spectrum of applications, from national security and nuclear reactor design to medical diagnostics, where the associated uncertainties can significantly impact outcomes. A substantial portion of uncertainty in nuclear data originates from the subjective biases in the evaluation process, a crucial phase in the nuclear data production pipeline. Recent advancements indicate that automation of certain routines can mitigate these biases, thereby standardizing the evaluation process and enhancing reproducibility. This research aims to provide a methodology, framework, and metrics for the validation of automated nuclear data evaluation software leveraging high-quality synthetic data that closely mimic real experimental observables. An introduced error metric provides a scale and intuitive measure of the evaluation quality by quantifying the estimate’s accuracy and performance across the specified energy range. Synthetic data provides access to experimental observables and underlying resonance parameters, enabling comparison of different evaluations. The methodology is demonstrated using Ta-181 isotope data in the resolved resonance region. The Automated Resonance Identification Subroutine (ARIS), which operates without prior resonance information, was used to test and showcase the framework’s capabilities utilizing the proposed error metrics. The results demonstrate the effectiveness of the proposed approach and framework for optimizing software parameters and testing hypotheses through “what-if” controlled experiments, such as modifying assumptions about experimental conditions or average resonance parameters.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗