Search NASASearch

SEARCH · Search NASA

Results for “computer information security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

Controlling Infrastructure Costs: Right-Sizing the Mission Control Facility

Johnson Space Center's Mission Control Center is a space vehicle, space program agnostic facility. The current operational design is essentially identical to the original facility architecture that was developed and deployed in the mid-90's. In an effort to streamline the support costs of the mission critical facility, the Mission Operations Division (MOD) of Johnson Space Center (JSC) has sponsored an exploratory project to evaluate and inject current state-of-the-practice Information Technology (IT) tools, processes and technology into legacy operations. The general push in the IT industry has been trending towards a data-centric computer infrastructure for the past several years. Organizations facing challenges with facility operations costs are turning to creative solutions combining hardware consolidation, virtualization and remote access to meet and exceed performance, security, and availability requirements. The Operations Technology Facility (OTF) organization at the Johnson Space Center has been chartered to build and evaluate a parallel Mission Control infrastructure, replacing the existing, thick-client distributed computing model and network architecture with a data center model utilizing virtualization to provide the MCC Infrastructure as a Service. The OTF will design a replacement architecture for the Mission Control Facility, leveraging hardware consolidation through the use of blade servers, increasing utilization rates for compute platforms through virtualization while expanding connectivity options through the deployment of secure remote access. The architecture demonstrates the maturity of the technologies generally available in industry today and the ability to successfully abstract the tightly coupled relationship between thick-client software and legacy hardware into a hardware agnostic "Infrastructure as a Service" capability that can scale to meet future requirements of new space programs and spacecraft. This paper discusses the benefits and difficulties that a migration to cloud-based computing philosophies has uncovered when compared to the legacy Mission Control Center architecture. The team consists of system and software engineers with extensive experience with the MCC infrastructure and software currently used to support the International Space Station (ISS) and Space Shuttle program (SSP).

Martin, Keith

A Central Asia Hydrologic Monitoring Dataset for Food and Water Security Applications in Afghanistan

From the Hindu Kush mountains to the Registan Desert, Afghanistan is a diverse landscape where droughts, floods, conflict, and economic market accessibility pose challenges for agricultural livelihoods and food security. The ability to remotely monitor environmental conditions is critical to support decision making for humanitarian assistance. The Famine Early Warning Systems Network (FEWS NET) Land Data Assimilation System (FLDAS) global and Central Asia data streams provide information on hydrologic states for routine integrated food security analysis. While developed for a specific project, these data are publicly available and useful for other applications that require hydrologic estimates of the water and energy balance. These two data streams are unique because of their suitability for routine monitoring, as well as for being a historical record for computing relative indicators of water availability. The global stream is available at ∼ 1-month latency, and monthly average outputs are on a 10 km grid from 1982–present. The second data stream, Central Asia (21–56°N, 30–100°E), at ∼ 1 d latency, provides daily average outputs on a 1 km grid from 2000–present. This paper describes the configuration of the two FLDAS data streams, background on the software modeling framework, selected meteorological inputs and parameters, and results from previous evaluation studies. We also provide additional analysis of precipitation and snow cover over Afghanistan. We conclude with an example of how these data are used in integrated food security analysis. For use in new and innovative studies that will improve understanding of this region, these data are hosted by U.S. Geological Survey data portals and the National Aeronautics and Space Administration (NASA). The Central Asia data described in this paper can be accessed via the NASA repository at https://doi.org/10.5067/VQ4CD3Y9YC0R (Jacob and Slinski, 2021), and the global data described in this paper can be accessed via the NASA repository at https://doi.org/10.5067/5NHC22T9375G (McNally, 2018).

Amy McNally

Cyber-Informed Engineering (CIE) Benefits Quantification: Recommendations for Consideration

Cyber-Informed Engineering (CIE) integrates engineering principles into the design, development, and operation of cyber-physical systems (CPS) to mitigate or eliminate the impact of cyber-enabled attacks. In July 2024, Idaho National Laboratory (INL) engaged MITRE researchers to investigate methods for systematically measuring the benefits of CIE implementation. This included evaluating the success and outcomes of CIE, identifying and quantifying the value of early adoption, and determining the business justification for its implementation, especially in existing infrastructure. MITRE reviewed existing methods in engineering and cybersecurity to understand how organizations prioritize security investments, considering their strengths, weaknesses, and relevance to CIE stakeholders. Based on this analysis, MITRE proposed potential approaches for quantifying CIE benefits and provided recommendations for INL's consideration.

42 ENGINEERING

Automating security monitoring and analysis for Space Station Freedom's electric power system

Operating a large, space power system requires classifying the system's status and analyzing its security. Conventional algorithms are used by terrestrial electric utilities to provide such information to their dispatchers, but their application aboard Space Station Freedom will consume too much processing time. A new approach for monitoring and analysis using adaptive pattern techniques is presented. This approach yields an on-line security monitoring and analysis algorithm that is accurate and fast; and thus, it can free the Space Station Freedom's power control computers for other tasks.

Dolce, James L.

Automating security monitoring and analysis for Space Station Freedom's electric power system

Operating a large, space power system requires classifying the system's status and analyzing its security. Conventional algorithms are used by terrestrial electric utilities to provide such information to their dispatchers, but their application aboard Space Station Freedom will consume too much processing time. A novel approach for monitoring and analysis using adaptive pattern techniques is presented. This approach yields an on-line security monitoring and analysis algorithm that is accurate and fast; and thus, it can free the Space Station Freedom's power control computers for other tasks.

Dolce, James L.

ARPA-E Grid Optimization (GO) Competition Challenge 1

The ARPA-E Grid Optimization (GO) Competition Challenge 1, from 2018 to 2019, focused on the basic Security Constrained AC Optimal Power Flow problem (SCOPF) for a single time period. The Challenge utilized sets of unique datasets generated by the ARPA-E GRID DATA program. Each dataset consisted of a collection of power system network models of different sizes with associated operating scenarios (snapshots in time defining instantaneous power demand, renewable generation, generator and line availability, etc.). The datasets were of two types: Real-Time, which included starting-point information, and Online, which did not. Week-Ahead data is also provided for some cases but was not used in the Competition. Although most datasets were synthetic and generated by GRIDDATA, a few came from industry and were only used in the Final Event. All synthetic Input Data and Team Results for the GO Competition Challenge 1 for the Sandbox, Trial Events 1 to 3, and the Final Event along with problem, format, scoring and rules descriptions are available here. Data for industry scenarios will not be made public. Challenge 1, a minimization problem, required two computational steps. Solver 1 or Code 1 solved the base SCOPF problem under a strict wall clock time limit, as would be the case in industry, and reported the base case operating point as output, which was used to compute the Objective Function value that was used as the scenario score. The feasibility of the solution was provided by the Solver 2 or Code 2, which solves the power flow problem for all contingencies based on the results from Solver 1. This is not normally done in industry, so the time limits were relaxed. In fact, there were no time limits for Trial Event 1. This proved to be a mistake, with some codes running for more than 90 hours, and a time limit of 2 seconds per contingency was imposed for all other events. Entrants were free to use their own Solver 2 or use an open-source version provided by the Competition. Containers, such as Docker, were considered to improve the portability of codes, but none that could reliably support a multi-node parallel computing environment, e.g., MPI, could be found. For more information on the competition and challenge see the "GO Competition Challenge 1 Information" and "GO Competition Challenge 1 Additional Information" resources below.

ACOPF

A Latency-Tolerant Partitioner for Distributed Computing on the Information Power Grid

NASA's Information Power Grid (IPG) is an infrastructure designed to harness the power of graphically distributed computers, databases, and human expertise, in order to solve large-scale realistic computational problems. This type of a meta-computing environment is necessary to present a unified virtual machine to application developers that hides the intricacies of a highly heterogeneous environment and yet maintains adequate security. In this paper, we present a novel partitioning scheme. called MinEX, that dynamically balances processor workloads while minimizing data movement and runtime communication, for applications that are executed in a parallel distributed fashion on the IPG. We also analyze the conditions that are required for the IPG to be an effective tool for such distributed computations. Our results show that MinEX is a viable load balancer provided the nodes of the IPG are connected by a high-speed asynchronous interconnection network.

Das, Sajal K.

Investigating Material Properties of Subsurface Rock Formations Modified by Engineering Mineral Precipitation (Final Scientific and Technical Report)

Montana State University’s (MSU) Energy Research Institute (ERI), in collaboration with the Center for Biofilm Engineering (CBE) and the Department of Civil Engineering (CE), has conducted a long‐term research program aimed at developing a novel cementing agent to address wellbore integrity and reduce the unwanted upward migration of fluids and greenhouse gases from the subsurface. The primary technology developed through this research program is known as ureolysis‐induced calcite precipitation (UICP), which harnesses bio‐chemical processes to precipitate calcium carbonate (CaCO 3 ). The same general process can also be called microbially-induced calcium carbonate precipitation (MICP) when microbes provide the process-catalyzing urease enzyme. Both terms are used in this report. Results have conclusively demonstrated that, if properly controlled, UICP can successfully seal fractures, high permeability zones, and compromised cement in the vicinity of wellbores and in nearby caprock. This technology has been successfully deployed to mitigate annular leakage in two test wells and over sixty commercial wells with a 100% success rate. This success in downhole deployment generates consideration of other subsurface applications where UICP could provide benefit to the energy sector, such as shale property modification for unconventional oil and gas recovery. The focus of this research project was to investigate fundamental material and mechanical properties of select shale cores and analyze how these properties change due to engineered mineral precipitation with the intent to control these properties to achieve a range of engineering objectives. Ultimately, the project aim was to identify valuable new areas where application of UICP might contribute to national energy security and environmental protection. The research workplan coupled UICP treatment of core samples, nuclear magnetic resonance (NMR) characterization, and mechanical strength testing at MSU with advanced X‐Ray micro-computed tomography (μCT) imaging and numerical modeling performed by collaborators at two national laboratories, the National Energy Technology Laboratory (NETL) and Lawrence Berkeley National Laboratory (LBNL). Experimental results are useful to inform geo-mechanical models which could be applied to predict mineralized rock formation behavior at field scale. Our findings suggest that NMR and μCT methods to detect and quantify biomineral formation in shale fractures are complementary and consistent with each other. Either could be used to estimate the volume of new mineral formed by UICP in shale fractures. The use of surfactants and guar gum to enhance biomineral precipitation in shale fractures merits further research. UICP can, under some conditions, increase the tensile strength of sealed shale fractures beyond that of the intact shale. These findings demonstrate that continued research in this area may be valuable to understanding and improving shale resource recovery techniques.

58 GEOSCIENCES

Enhancing Cloud Cybersecurity: Prescriptive Controls for Operational Technology

This whitepaper provides strategic insights and recommendations into security cloud-based solutions for electric utilities, encompassing operational technology (OT), virtual power plants (VPP), distributed energy resources (DERs), applications, networks, and data storage as they transition to and leverage cloud infrastructure through managed service providers (MSPs) and cloud service providers (CSPs). Principles derived from established frameworks serve as a foundation for best practices across cybersecurity projects and remove the constraints of settling on a single framework. For organizations that prefer not to integrate a specific framework altogether, elements of the proposed approach could be adopted or tailored to best fit defined requirements and expected functionalities. The Cirrus assessment, a utility cloud feasibility tool, and the roadmap it provides serve as a precursor to this paper, which seeks to be a valuable resource for defining next steps following cloud technology integration feasibility appraisal. With its comprehensive approach to adoption, the Cirrus framework offers strategic guidance on responsibly preparing for or deploying a utility cloud solution. The previously published whitepaper, “Use Case-Informed Framework for Utility Cloud Migration,” details the guiding strategy, research, and deployment of cloud solutions within electric and interconnected grid systems. Before implementing the controls suggested in this document, it is recommended that stakeholders complete Cirrus's cloud integration assessment and pair the results with their unique cybersecurity controls to form a comprehensive cloud-based utility cybersecurity plan. The Cirrus outcome will consider a series of future architectures for the grid before and after the energy transition and evaluate the arguments for and against cloud applications for each electric and interconnected grid layer. This document is a companion to the original whitepaper, "Use Case-Informed Framework for Utility Cloud Migration" to further identify and recommend security controls based on Cirrus’s cloud integration assessment output. The following whitepaper outlines the cybersecurity controls that secure cloud-service models pertinent to the electric sector using the predefined categories identify, protect, detect, and respond and recover. The objective is to outline prescriptive security controls based on the type of architecture and data stored in the cloud. The focus includes dissecting the shared responsibility model and elucidating what on-premises Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) entail. A pivotal consideration in this context is allocating responsibility for foundational cybersecurity aspects—having used Cirrus for the cloud integration assessment. The ensuing controls detailed herein also represent a checklist of controls necessary for a secure cloud transition, equipping utilities with the knowledge to navigate this digital transformation with confidence and strategic foresight in a safe and responsible manner.

42 ENGINEERING

Antiterrorist Software

In light of the escalation of terrorism, the Department of Defense spearheaded the development of new antiterrorist software for all Government agencies by issuing a Broad Agency Announcement to solicit proposals. This Government-wide competition resulted in a team that includes NASA Lewis Research Center's Computer Services Division, who will develop the graphical user interface (GUI) and test it in their usability lab. The team launched a program entitled Joint Sphere of Security (JSOS), crafted a design architecture (see the following figure), and is testing the interface. This software system has a state-ofthe- art, object-oriented architecture, with a main kernel composed of the Dynamic Information Architecture System (DIAS) developed by Argonne National Laboratory. DIAS will be used as the software "breadboard" for assembling the components of explosions, such as blast and collapse simulations.

Clark, David A.

Tools for Administration of a UNIX-Based Network

Several computer programs have been developed to enable efficient administration of a large, heterogeneous, UNIX-based computing and communication network that includes a variety of computers connected to a variety of subnetworks. One program provides secure software tools for administrators to create, modify, lock, and delete accounts of specific users. This program also provides tools for users to change their UNIX passwords and log-in shells. These tools check for errors. Another program comprises a client and a server component that, together, provide a secure mechanism to create, modify, and query quota levels on a network file system (NFS) mounted by use of the VERITAS File SystemJ software. The client software resides on an internal secure computer with a secure Web interface; one can gain access to the client software from any authorized computer capable of running web-browser software. The server software resides on a UNIX computer configured with the VERITAS software system. Directories where VERITAS quotas are applied are NFS-mounted. Another program is a Web-based, client/server Internet Protocol (IP) address tool that facilitates maintenance lookup of information about IP addresses for a network of computers.

LeClaire, Stephen

(ODIN): An Open Source, Low-Latency Data Integration & Visualization Framework for the NASA System Wide Safety Project's Disaster Response Safety Demonstration Series

The Open Data Integration Framework (ODIN) is an open source, low latency data integration and visualization framework (https://github.com/NASARace/race-odin) developed under NASA’s System WideSafety Program to demonstrate new safety capabilities designed to improve US airspace operations. Safety demonstrations are a set of increasingly complex (from public safety perspective) disaster response scenarios under which air systems must operate with increased capacity and include: 1) Wildland fire response, 2) Hurricane relief and recovery, 4) Emergency medical delivery via UAS and 4) Urban disaster relief. To accommodate disaster response, ODIN is field deployable and can scale on one or more multi-core, commodity laptops operating with full to limited or intermittent internet connectivity, conditions likely encountered during operations. ODIN runs as webserver with local, persistent data storage to serve either public or a secured, ad hoc network (e.g., an incident command post). The current released ODIN, ODIN-Fire is tailored for wildland fire management incorporating information on satellite overpasses with links to the near real-time data and imagery from the respective agencies. Included are winds data, an important variable for emergency responders and airspace operations, and high-resolution wind forecasts generated by super-computing resources and ingested into ODIN. As an open-source project, ODIN has attracted interest from multiple entities. We will show how 1) a commercial field instrument and data provider uses ODIN to help users visualize, publish and integrate their in-situ sensor network data and 2) ODIN’s capabilities to ingest, integrate and display near-real time satellite data with air traffic and a USFS winds forecast model used in fire response and post-fire assessment. Within NASA ODIN demonstrated novel, near terminal airspace safety capabilities for a project close-out event and previously it monitored the national airspace in real-time to meet an agency milestone. ODIN is presently under development for the anticipated hurricane relief and response demonstration notionally scheduled for the 2025-27 time frame and is available from NASA's github at the above link.

Aeronautics

Resonant metasurface‐enabled quantum light sources for single‐photon emission and entangled photon‐pair generation

Light encodes information in multiple degrees of freedom (e.g., frequency, amplitude, and phase), enabling high‐speed, high‐bandwidth communication through fiber optics. Unlike classical light, quantum light (single or entangled photons) can transmit quantum states over long distances without loss of coherence, thereby coherently interconnecting quantum nodes for distributed quantum entanglement. Quantum light sources are critical for developing scalable quantum networks aimed at distributed quantum computing, quantum teleportation, and secure quantum communications. However, existing quantum light sources suffer from limited integrability, insufficient spectral and spatial tunability, and inefficiencies in achieving mass‐produced, deterministic, on‐demand quantum light generation. These limitations significantly hinder progress toward direct, on‐chip integration with quantum processing units and detectors – an essential step toward scalable quantum networks. Resonant metasurfaces that leverage photonic modes – such as Mie resonances, guided‐mode resonances, or symmetry‐protected bound states in the continuum – offer strong spatial and temporal confinement of electromagnetic fields, characterized by high quality factors and small mode volumes. These metasurfaces greatly enhance linear and nonlinear light‐matter interactions, making them ideal for efficient on‐chip quantum light generation and manipulation. Here, we describe recent advances in nanoscale quantum light sources and quantum photonic state manipulation enabled by resonant metasurfaces. We also provide an outlook on next‐generation miniaturized quantum light sources achievable through materials innovations in quantum emitters, the co‐design of resonant metasurfaces, and ultimately, the heterogeneous integration of emerging layered van der Waals materials with resonant metasurfaces.

71 CLASSICAL AND QUANTUM MECHANICS, GENERAL PHYSIC

How Autonomous Intelligent Systems Can Facilitate Earth-independent Medical Care: Going Beyond Telepresence

During the last decade, teleoperated robotic systems have extended humans’ sensorimotor competence to digitally fly beyond the physical barrier of distance and scale and thus transmit sensorimotor skills of the human through direct communication. Telepresence capabilities have enabled tele-physical remote access at small scales thanks to telerobotic mediums. Although the concept was initially motivated by space applications, such technologies quickly have expanded into the medical domain and resulted in teleoperated medical robots, including telerobotic surgical systems (such as the da Vinci surgical system). Effective telepresence fundamentally depends on an agile, reliable, and secure communication medium that can transmit real-time information between the operator and a remote device. However, direct telepresence may not be achievable for long-duration exploration spaceflight missions. Thus, autonomous systems and local intelligence represent potential solutions to the aforementioned issues. One example solution employs demonstration systems which enable learning from the pre-captured inputs of a skilled human operator. These will be computationally modeled and later probabilistically replicated toward the completion of remote physical tasks when direct telepresence is not viable - such as under communication blackout conditions. In other words, trained autonomous systems (e.g., robots) can perform remote operations that mimic the physical performance of experts during remote operations/training. Beyond learning the physics of the task, autonomous agents can also be used to conduct algorithmic decision-making that mimics the higher-level cognition of the expert. Thus, using an autonomous system, pre-trained cognitive and manipulation-based skills can be leveraged (acquired during pre-mission events) to produce digital twins of an intelligent operator. Such systems can be used for the real-time conduction of intricate tasks in complex and unstructured environments. Such systems will operationalize “cognitive digital twins” and can expand the reach of human cognition and manipulation through the power of data-driven learning from demonstration algorithms. This system category will be discussed as a fully autonomous operation in this talk. In addition to the above, we will also propose and discuss the possibility of partial-automation using remote intelligence and remote sensing. In contrast to full automation, partial automation can close the loop through a local operator equipped with augmented sensory awareness through wearable systems. Such technologies will allow the local operator to conduct delicate tasks while being guided using sensory augmentation and being monitored to gauge her/his level of cognitive focus and performance. The difference with the previous category is that a remote human will conduct the task. Further, rather than making a digital twin of human cognition, we will augment the control inputs of the local human to match those of the skilled expert operator who is not accessible in real-time. Going beyond classic telepresence and thus approaching intelligent telepresence, our vision is that autonomous agents will eventually enable the safe, consistent and efficient delivery of complex, remote and smart medical care during space exploration across operators in an Earth-independent fashion. We will discuss our collective vision from NASA and MERIIT@NYU lab in this talk.

Telepresence

Pacific Northwest National Laboratory Annual Site Environmental Report for Calendar Year 2023

Pacific Northwest National Laboratory (PNNL), one of the U.S. Department of Energy (DOE) Office of Science’s 10 national laboratories, provides innovative science and technology development in the areas of energy and the environment, fundamental and computational science, and national security. There are three DOE offices within the Richland area. Two are responsible for the Hanford Site, whereas the Pacific Northwest Site Office oversees PNNL. PNNL prepares an Annual Site Environmental Report to meet the requirements of DOE Order 231.1B, Environment, Safety and Health Reporting, and DOE Order 458.1, Radiation Protection of the Public and the Environment, thus assuring that the public is informed of any PNNL-Richland campus or PNNL-Sequim campus event that could adversely affect the health and safety of the public, site staff, or the environment. The report provides a synopsis of ongoing environmental management performance and compliance activities for operations that occur at the PNNL-Richland campus in Richland, Washington, and at the PNNL-Sequim campus near Sequim, Washington. It describes the location of and background for each facility; addresses compliance with applicable DOE, federal, state, and local regulations, and site-specific permits; documents environmental monitoring efforts and their status; presents potential radiation doses to staff and the public in the surrounding areas; and describes DOE-required data quality assurance methods used for data verification. The ASER report describes Compliance with Federal, State, and Local Laws and Regulations in 2023, Environmental Sustainability, Environmental monitoring and dose assessment, Natural and Cultural Resource Management, and Quality Assurance activities that took place during Calendar Year 2023.

40 CFR 61 Subpart H

Cyber-Informed Engineering (CIE) – Engineered Controls Database and Use

Cyber-Informed Engineering (CIE) addresses the reality that cyber-attacks on engineered systems can have consequences far beyond data loss or disruption of digital networks. When control systems are compromised, safety, reliability, and performance of the physical process itself may be threatened. This database is meant to establish clear examples and guidance for defining and applying engineered controls in CIE. It explains what engineered controls are, how they differ from information security measures, and how they are integrated into system design. The goal is to ensure that resilience is engineered into systems from the outset. Unlike cybersecurity protections that defend the digital layer, engineered controls act directly at the physical and algorithmic levels to guarantee that unacceptable consequences are prevented or limited. CIE keeps the consequences of a cyber attack from impacting the safety, reliability, and performance of engineered systems.

42 - ENGINEERING

Radsource Mr: Mixed Reality Planning Tool For Radioactive Recovery

The RadSource MR system leverages Meta Quest 3's advanced mixed reality capabilities to create a comprehensive spatial planning platform for end-of-life sealed radioactive source recovery operations. The application utilizes the Quest 3's high-resolution passthrough cameras and spatial mapping algorithms to generate accurate 3D environmental models. Core technical components include: (1) Real-time spatial measurement algorithms calculating distances, angles, slopes, and surface areas with sub-centimeter accuracy; (2) Virtual object placement system allowing users to position digital representations of recovery equipment (trailers, containment vessels, protective barriers) within the real environment; (3) Voice recording and annotation system for hands-free documentation in protective equipment; (4) 3D mesh capture and storage capabilities for post-operation analysis and regulatory documentation. (5) Procedure documentation is available for viewing in Mixed Reality, providing an innovative and convenient way to access the information during pre-visit and inspection activities. (6) Support for screen capture for the view for real world and virtual objects together to use it later for planning. The system integrates computer vision techniques for environmental understanding, spatial mathematics for precise measurements, and human-computer interaction principles optimized for hazardous environment operations. Data persistence allows teams to save and share planning sessions across multiple stakeholders while maintaining operational security requirements.

Khadka, Rajiv [Idaho National Laboratory (INL), Id