Search NASA⌕ Search

SEARCH · Search NASA

Results for “trusted design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 145 records · Page 8

Trusted Autonomy for Space Flight Systems

NASA has long supported research on intelligent control technologies that could allow space systems to operate autonomously or with reduced human supervision. Proposed uses range from automated control of entire space vehicles to mobile robots that assist or substitute for astronauts to vehicle systems such as life support that interact with other systems in complex ways and require constant vigilance. The potential for pervasive use of such technology to extend the kinds of missions that are possible in practice is well understood, as is its potential to radically improve the robustness, safety and productivity of diverse mission systems. Despite its acknowledged potential, intelligent control capabilities are rarely used in space flight systems. Perhaps the most famous example of intelligent control on a spacecraft is the Remote Agent system flown on the Deep Space One mission (1998 - 2001). However, even in this case, the role of the intelligent control element, originally intended to have full control of the spacecraft for the duration of the mission, was reduced to having partial control for a two-week non-critical period. Even this level of mission acceptance was exceptional. In most cases, mission managers consider intelligent control systems an unacceptable source of risk and elect not to fly them. Overall, the technology is not trusted. From the standpoint of those who need to decide whether to incorporate this technology, lack of trust is easy to understand. Intelligent high-level control means allowing software io make decisions that are too complex for conventional software. The decision-making behavior of these systems is often hard to understand and inspect, and thus hard to evaluate. Moreover, such software is typically designed and implemented either as a research product or custom-built for a particular mission. In the former case, software quality is unlikely to be adequate for flight qualification and the functionality provided by the system is likely driven largely by the need to publish innovative work. In the latter case, the mission represents the first use of the system, a risky proposition even for relatively simple software.

Freed, Michael↗

Metrics and Benchmarks for Visualization

What is a "good" visualization? How can the quality of a visualization be measured? How can one tell whether one visualization is "better" than another? I claim that the true quality of a visualization can only be measured in the context of a particular purpose. The same image generated from the same data may be excellent for one purpose and abysmal for another. A good measure of visualization quality will correspond to the performance of users in accomplishing the intended purpose, so the "gold standard" is user testing. As a user of visualization software (or at least a consultant to such users) I don't expect visualization software to have been tested in this way for every possible use. In fact, scientific visualization (as distinct from more "production oriented" uses of visualization) will continually encounter new data, new questions and new purposes; user testing can never keep up. User need software they can trust, and advice on appropriate visualizations of particular purposes. Considering the following four processes, and their impact on visualization trustworthiness, reveals important work needed to create worthwhile metrics and benchmarks for visualization. These four processes are (1) complete system testing (user-in-loop), (2) software testing, (3) software design and (4) information dissemination. Additional information is contained in the original extended abstract.

Uselton, Samuel P.↗

GridSTIX

SF-25-112 Grid-STIX is a comprehensive extension of the STIX (Structured Threat Information Expression) 2.1 ontology specifically designed for electrical grid cybersecurity applications. This ontology provides a standardized, machine-readable framework for modeling grid assets, operational technology devices, threats, vulnerabilities, supply chain risks, and security relationships in electrical power systems. ## Key Features - **Comprehensive Grid Coverage**: Physical assets, OT devices, grid components, sensors, and energy storage systems - **Zero Trust Architecture**: Policy decision points, enforcement points, trust brokers, and continuous monitoring - **AMI Infrastructure**: Advanced metering networks, head-end systems, mesh gateways, and MDM systems - **Advanced Security Modeling**: Attack patterns, vulnerabilities, mitigations, and supply chain risks - **Critical Grid Relationships**: Power flow, protection, control, and synchronization relationships - **Supply Chain Security**: Supplier modeling, country of origin tracking, and risk assessment - **Protocol Support**: DNP3, Modbus, IEC 61850, IEC 60870-5-104, OPC-UA, and IEEE standards - **Python Code Generation**: Automated STIX-compliant Python class generation from ontologies - **Interactive Visualization**: Enhanced HTML network graphs with grid-specific categorization - **STIX 2.1 Compliance**: Full compatibility with STIX threat intelligence ecosystem

Blakely, Benjamin [Argonne National Laboratory (AN↗

TRUST Contact Thermal Conductance (TRUST-CTC) Report: FY25

The objective of the Delivery Environments (DE) Testbeds to Reduce Uncertainties in Simulations and Tests (TRUST) project is to quantify and help increase confidence in specific areas of computational and experimental capabilities that are applicable to current and future delivery environments [1]. More complete quantification of confidence in experimental and computational capabilities and the sufficient increase of confidence in those capabilities is critical to improving weapons engineering design, qualification, and assessment efforts that are critical to the current and future stockpile. Staff development will include cross-discipline collaboration to provide engineers with experience in both numerical simulations and experimental methods. This work uses and provides feedback on analysis tools and experimental results databases for efficient and responsive engineering which are currently under development.

42 ENGINEERING↗

Estimating Future Changes of Energy Demand for Heating and Cooling Buildings at NASA Centers GC23J-1198

With its unique and trusted earth observations, NASA is a critical source in informing decisions that will help achieve the U.S. goal of Net-Zero Greenhouse Gas (GHG) Emissions by 2050. NASA’s Prediction of Worldwide Energy Resource (POWER) project facilitates the use of NASA Earth Science data holdings within the energy, agricultural, and building heating/cooling design industries. POWER packages solar and meteorological data from several NASA projects in a user friendly GIS-enabled web services system (https://power.larc.nasa.gov). As part of the development of new data products to support the energy and building heating/cooling design communities, we estimate the changes in energy required to heat and cool buildings in the future climate at 14 different NASA site locations spread throughout the continental United States, as projected by CMIP6 climate models under different emissions scenarios. Bias-corrected downscaled time series of meteorological variables are taken from NASA Earth Exchange (NEX) Global Daily Downscaled Projections (GDDP-CMIP6) downscaled climate model data. The spread between the different model projections is accounted for by analyzing both the ensemble average of 22 CMIP6 models and 6 representative models with different climate sensitivities and different interannual variability. Changes in energy use are estimated in two ways. First, changes in the total annual heating and cooling degree days (HDD and CDD, respectively) are calculated relative to the current climate. This is done at all 14 sites. Second, the downscaled time series are used as inputs into RETScreen(R), a clean energy management decision tool, to give an estimate of heating/cooling energy use for a typical office building. We use this estimation method with model data at Langley Research Center. In the next 50 years, the annual total of HDD (CDD) is projected to decrease by 8-38% (increase by 5-28%) at all sites, with the increase in CDD typically a larger magnitude the decrease in HDD. For a typical small office building at Langley Research Center, the amount of energy needed to cool increases by 33-54% and the amount of energy to heat decreases by 29-40%. POWER is working to develop long term climate data services based on these results to include in future data products to provide to users.

Bradley M. Hegyi↗

Trust Control of VTOL Aircraft Part Deux

Thrust control of Vertical Takeoff and Landing (VTOL) aircraft has always been a debatable issue. In most cases, it comes down to the fundamental question of throttle versus collective. Some aircraft used throttle(s), with a fore and aft longitudinal motion, some had collectives, some have used Thrust Levers where the protocol is still "Up is Up and Down is Down," and some have incorporated both throttles and collectives when designers did not want to deal with the Human Factors issues. There have even been combinations of throttles that incorporated an arc that have been met with varying degrees of success. A previous review was made of nineteen designs without attempting to judge the merits of the controller. Included in this paper are twelve designs entered in competition for the 1961 Tri-Service VTOL transport. Entries were from a Bell/Lockheed tiltduct, a North American tiltwing, a Vanguard liftfan, and even a Sikorsky tiltwing. Additional designs were submitted from Boeing Wichita (direct lift), Ling-Temco-Vought with its XC-142 tiltwing, Boeing Vertol's tiltwing, Mcdonnell's compound and tiltwing, and the Douglas turboduct and turboprop designs. A private party submitted a re-design of the Breguet 941 as a VTOL transport. It is important to document these 53 year-old designs to preserve a part of this country's aviation heritage.

Thrust control↗

Status Report on Nuclear Stage Definition

This status report on nuclear stage definition should convey the message that a comprehensive analysis is underway, embracing many vehicle concepts and the full range of expected RNS operations. Flexible use in the future space program is one objective; economy and ease of operations are also major goals. Not until details unfold in the several mission areas and in definitions of interrelated systems can the RNS studies be narrowed down to fewer alternatives. Consequently, the current phase of the NSSD study is emphasizing (1) in-space operations, especially as they are affected by aftercooling and the radiation environment of the stage, and (2) RNS concepts in which the unique features of nuclear propulsion are utilized or designed around. Studies to date indicate that significant benefits can be realized through use of an RNS in the missions of the 1980's. Tn the broader context of technology advancement and foundation-building for later decades, the development of a reusable nuclear stage is highly desirable. The next year's efforts will, we trust, bring us much nearer to a full understanding of the RNS and its role in the future space program.

Johnson, Paul G.↗

Countering Weapons of Mass Destruction (CWMD) Zero Trust Framework: CWMD Zero Trust Principles Model

The research focuses on the critical need for enhanced cybersecurity within the Countering Weapons of Mass Destruction (CWMD) Office, specifically targeting Chemical, Biological, Radiological, and Nuclear devices. Traditional perimeter-based security models are insufficient against modern cyber threats, prompting a shift toward Zero Trust principles (ZTP) that emphasize continuous verification and stringent security for all devices. Federal directives mandate the adoption of Zero Trust (ZT) across agencies, supported by guidelines from National Institute of Standards and Technology (NIST), U.S. Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA), U.S. Department of Defense (DoD) and National Security Agency (NSA). The research involved mapping ZT guidance from these agencies to develop tailored CWMD ZTP. The study identified gaps and areas for improvement, including clear transitional guidance from traditional to ZT architectures and the focus on explicit cross cutting capabilities. Design improvements are recommended to ensure increased comprehensive protection and resilience against sophisticated cyber threats for Chemical, Biological, Radiological, and Nuclear (CBRN) devices. Collaborative efforts among federal agencies are essential for the successful deployment of an optimized ZT guidance.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Application of Human-Autonomy Teaming to an Advanced Ground Station for Reduced Crew Operations

Within human factors there is burgeoning interest in the "human-autonomy teaming" (HAT) concept as a way to address the challenges of interacting with complex, increasingly autonomous systems. The HAT concept comes out of an aspiration to interact with increasingly autonomous systems as a team member, rather than simply use automation as a tool. The authors, and others, have proposed core tenets for HAT that include bi-directional communication, automation and system transparency, and advanced coordination between human and automated teammates via predefined, dynamic task sequences known as "plays." It is believed that, with proper implementation, HAT should foster appropriate teamwork, thus increasing trust and reliance on the system, which in turn will reduce workload, increase situation awareness, and improve performance. To this end, HAT has been demonstrated and/or studied in multiple applications including search and rescue operations, healthcare and medicine, autonomous vehicles, photography, and aviation. The current paper presents one such effort to apply HAT. It details the design of a HAT agent, developed by Human Automation Teaming Solutions, Inc., to facilitate teamwork between the automation and the human operator of an advanced ground dispatch station. This dispatch station was developed to support a NASA project investigating a concept called Reduced Crew Operations (RCO); consequently, we have named the agent R-HATS. Part of the RCO concept involves a ground operator providing enhanced support to a large number of aircraft with a single pilot on the flight deck. When assisted by R-HATS, operators can monitor and support or manage a large number of aircraft and use plays to respond in real-time to complicated, workload-intensive events (e.g., an airport closure). A play is a plan that encapsulates goals, tasks, and a task allocation strategy appropriate for a particular situation. In the current implementation, when a play is initiated by a user, R-HATS determines what tasks need to be completed and has the ability to autonomously execute them (e.g., determining diversion options and uplinking new routes to aircraft) when it is safe and appropriate. R-HATS has been designed to both support end users and researchers in RCO and HAT. Additionally, R-HATS and its underlying architecture were developed with generalizability in mind as a modular software applicable outside of RCO/aviation domains. This paper will also discuss future further development and testing of RHATS.

automation↗

Code Coverage Status of the ARC Code DIF3D

The Argonne Reactor Code (ARC) software system supports users in their fast reactor design goals by providing neutronic, thermal-hydraulic, and structural analysis capabilities. DIF3D plays a pivotal role in the ARC system as the primary homogenized assembly neutronic calculation methodology for fast reactor problems. Over its 40 years history, ARC software usage with DIF3D has been applied to numerous fast and thermal spectrum reactor analysis projects with good to excellent comparison against experiments. With continued improvement of computation resources, many of the geometry modeling capabilities in DIF3D that were primarily used in low order schemes are not really needed anymore. Today, the diffusion and transport capabilities of DIF3D-VARIANT are primarily used in the reactor design process with some scattered usage of DIF3D-FD and DIF3D-Nodal. In recent work, the DIF3D software verification was completed for DIF3D-FD and DIF3D-VARIANT on the geometry options used in the Versatile Test Reactor project. While we can be confident that these capabilities of DIF3D are well used and thus trusted, it does not demonstrate that all possible input options of DIF3D are actually working, but just those that were tested as part of VTR are and that they are correct. Thus, the purpose of the present work is to identify a set of test problems for DIF3D and assess the code coverage of DIF3D for those test problems. The goal is to document what parts of the existing DIF3D code are touched by the set of test problems and which are not. Because the verification work done on DIF3D-VARIANT and DIF3D-FD was focused on the most common uses of DIF3D for fast reactor analysis, the code coverage assessment of those capabilities is the highest priority. This will ensure that nothing is being missed by the existing verification test problems that DIF3D relies upon. The DIF3D-Nodal capability will also be inspected for code coverage as part of this work to further ensure that regular regression testing of DIF3D will trap any likely errors the end user might experience with the DIF3D software. The code coverage analysis of DIF3D was performed with the Code Coverage Tool of the Intel Fortran compiler which requires modifications to the compilation of DIF3D. The detailed coverage tables are given for each submodule of DIF3D separately, and for the submodules which are primarily developed for DIF3D, most of the source files could be at least partially touched. Most of the uncovered parts/files could be easily ignored, because they are either for error message and debugging output or obviously not needed by DIF3D. Out of the entire source codes of DIF3D, only a few uncovered modules deserve further investigation.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

TrustDER: Trusted, Private and Scalable Coordination of Distributed Energy Resources

In this project, the Stanford and SLAC Teams have developed a Trusted, Private and Scalable platform for coordinating Coordination of Distributed Energy Resources (TrustDER). This is a layered system that ensures private, trusted and scalable coordination and monitoring of DERs. It accommodates a variety of resources, such as solar generation, gensets and loads, with a particular focus on battery systems-based resources, as they are a transformational technology experiencing fast growth in adoption by large critical facilities. The platform can be used as standalone or added to existing aggregation systems to enable trust, privacy and resilience. TrustDER consists of layers that address each of the shortcomings of the existing state of the art. Each layer in the platform can operate independently but provides information to the layers above it to enable a novel form of overall coordination architecture. The project consists of several tasks, with each task dedicated to the design of each layer. Task 2 Resource Virtualization defined a software abstraction layer for distributed energy resources (DERs). The goal of this abstraction was to simplify the implementation of algorithms utilizing cooperation of DERs resources in a variety of use cases. Task 3 is on Secure ID for Asset Authentication. Identity Management Systems (IDMS) are a foundational infrastructure for interactions between entities (organizations, users, devices, and services). Secure ID is blockchain-based a distributed identity management system allowing (1) identity provisioning, (2) authentication, (3) authorization, and (4) identity data sharing for IoT-enabled assets on the electricity grid. In this project, the SLAC team focused on designing and testing Keymaker, a protocol for authenticating device identity managed by Secure ID. Task 5 Private and Safe Integration is focused on the design and evaluation of a DER cooperation scheme which allows for the aggregation of DERs without impacting network reliability. The approach is designed based on realistic assumptions regarding data availability, communication infrastructure limitations, and privacy. Task 6 Scalable Distributed Privacy for Information explored how virtualized batteries could be managed privately. Specifically, it examined the case in which a principal provides a partitioned battery to multiple clients. Task 7 Use Cases was to ensure that this technology was applied in relevant situations and scenarios. Primarily, this means that virtualization needed to be employed in a manner that either improved flexibility, bolstered security or privacy, or decreased costs.

25 ENERGY STORAGE↗

Report of the 2025 Workshop on Next-Generation Ecosystems for Scientific Computing: Harnessing Community, Software, and AI for Cross-Disciplinary Team Science

This report summarizes insights from the 2025 Workshop on Next-Generation Ecosystems for Scientific Computing: Harnessing Community, Software, and AI for Cross-Disciplinary Team Science, which convened more than 40 experts from national laboratories, academia, industry, and community organizations to chart a path toward more powerful, sustainable, and collaborative scientific software ecosystems. To address urgent challenges at the intersection of high-performance computing (HPC), AI, and scientific software, participants envisioned agile, robust ecosystems built through socio-technical co-design—the intentional integration of social and technical components as interdependent parts of a unified strategy. This approach combines advances in AI, HPC, and software with new models for cross-disciplinary collaboration, training, and workforce development. Key recommendations include building modular, trustworthy AI-enabled scientific software systems; enabling scientific teams to integrate AI systems into their workflows while preserving human creativity, trust, and scientific rigor; and creating innovative training pipelines that keep pace with rapid technological change. Pilot projects were identified as near-term catalysts, with initial priorities focused on hybrid AI/HPC infrastructure, cross-disciplinary collaboration and pedagogy, responsible AI guidelines, and prototyping of public-private partnerships. This report presents a vision of next-generation ecosystems for scientific computing where AI, software, hardware, and human expertise are interwoven to drive discovery, expand access, strengthen the workforce, and accelerate scientific progress.

97 MATHEMATICS AND COMPUTING↗

Scale-Bridging Optimization Framework for Desalination Integrated Produced Water Networks

In this work, we develop a Pyomo-based non-linear optimization strategy that includes rigorous MVR models. The detailed desalination unit is integrated into the multiperiod produced water network problem using the trust region filter (TRF) method. TRF decomposes the integrated problem into a master problem consisting of the network variables and a simplified surrogate model for the detailed desalination unit. The surrogate is updated using zero and first-order corrections from the optimal solution of the detailed models at every iteration. This framework allows us to co-optimize the design of the desalination units and operating policy for the multiperiod network. A common design is ensured across all periods using global capacity constraints. We validate the solution obtained using the TRF method by solving the full integrated problem for small network instances and show our results on real case studies on produced water networks from the Permian and Appalachian basins. In this work, we describe our TRF formulation, give details on our implementation in Pyomo, and analyze the results obtained by solving the optimization problem using IPOPT. We also present a discussion on the computational efficiency and scaling using the TRF approach against a full-scale integration of the rigorous models within the water network.

Naik, Sakshi↗

TRUST Sensors in Environments: Thermocouples (SE-TC) Report Release FY24

The objective of the Delivery Environments (DE) Testbeds to Reduce Uncertainty in Simulations and Tests (TRUST) project is to quantify and help increase confidence in specific areas of computational and experimental capabilities that are applicable to the development, on-target assessment, and qualification of current and future delivery environments. More complete quantification of confidence in experimental and computational capabilities and the sufficient increase of confidence in those capabilities is critical to improving weapons engineering design, qualification, and assessment efforts that are critical to the current and future stockpile. This work uses and provides feedback on analysis tools and experimental results databases for efficient and responsive engineering which are currently under development.

42 ENGINEERING↗

Don't Trust a Management Metric, Especially in Life Support

Goodhart's law states that metrics do not work. Metrics become distorted when used and they deflect effort away from more important goals. These well-known and unavoidable problems occurred when the closure and system mass metrics were used to manage life support research. The intent of life support research should be to develop flyable, operable, reliable systems, not merely to increase life support system closure or to reduce its total mass. It would be better to design life support systems to meet the anticipated mission requirements and user needs. Substituting the metrics of closure and total mass for these goals seems to have led life support research to solve the wrong problems.

life support↗

An optimization-based approach to tailor the mechanical response of soft metamaterials undergoing rate-dependent instabilities

An optimization-based design framework is proposed to tune the response of soft metamaterials involving both geometric instabilities and nonlinear viscoelastic material behavior. Designing the response of soft metamaterials to harness instabilities and undergo large, tailored configuration changes will enable advancements in soft robotics, shock and vibration mitigation, and flexible electronics. In line with the metamaterial concept, the response of these materials is governed to a large extent by the geometric and topological makeup of their small-scale features. However, the link between structure and response is less intuitive for soft metamaterials due to their reliance upon highly nonlinear responses triggered by geometric instabilities. This is further complicated by the effects of viscoelastic relaxation, which recent studies have shown to alter the emergence of instabilities in non-intuitive ways. Here, these effects are accounted for in our framework to achieve various design objectives, including tailored force–displacement response and maximized energy absorption from both geometric and material effects. To fully automate this process, it is essential to have a completely robust equation solver for forward problems involving instabilities and viscoelastic relaxation. We achieve this by casting the search for stable mechanical equilibrium — i.e. the forward problem — as a minimization problem and utilize a trust region algorithm to robustly handle instabilities and follow energetically-favorable equilibrium paths through critical points.

97 MATHEMATICS AND COMPUTING↗

The Essence of Cryptol: A Denotational Cryptol Interpreter in Coq for Foundational Assurances for Quantum Resistant Cryptosystems

Systems of the utmost consequence need a means to establish authenticity of software and data. Cryptosystems implement authentication, but can be vulnerable to cryptographic and implementation attacks. With the threat of quantum cryptographic attacks, “post-quantum” cryptosystems (PQCs) must be henceforth used in these systems. However, the new cryptography needs new ways to, rigorously and machine-checkably, prove systems free of vulnerabilities. We propose a retargetable capability to rapidly instantiate proven correct postquantum cryptosystems through novel proof-carrying synthesis and proof-automation technique, extending those proven successful on existing systems. This capability is crucial to meeting the cryptographic requirements for future high-consequence systems. Since specifications for high consequence cryptography are presently captured in a domain specific language known as Cryptol. While this can enable convenient fully automated reasoning about Cryptol specificaitons and implementations via the Software Analysis Workbench (SAW), Cryptol has expressivity gaps, so that cryptosystems with probabilistic programming features like Falcon cannot be fully expressed in the language. Moreover, SAW’s automation fails for programs and specificaitons with inductive and recursive structure, as in the Sphincs+ PQC. Finally, Cryptol and SAW together represent some 200,000 lines of unverified Haskell, so that the any guarantees about high consequence cryptography are presently contingent on a large, unverified, yet trusted computing base. The first step of the larger project of agile, assured crpytography is therefore to provide a formal, mechanized semantics for Cryptol, so that the specifications expressed by cryptographers in Cryptol can be reasoned about and compiled into performant implementations with a foundational, machine checkable certificate of correctness. This report describes our work on this first step, culminating in the design of a certified denotational interpreter, in Coq, for core Cryptol.

97 MATHEMATICS AND COMPUTING↗

Towards Informing an Intuitive Mission Planning Interface for Autonomous Multi-Asset Teams via Image Descriptions

Establishing a basis for certification of autonomous systems using trust and trustworthiness is the focus of Autonomy Teaming and TRAjectories for Complex Trusted Operational Reliability (ATTRACTOR). The Human-Machine Interface (HMI) team is working to capture and utilize the multitude of ways in which humans are already comfortable communicating mission goals and translate that into an intuitive mission planning interface. Several input/output modalities (speech/audio, typing/text, touch, and gesture) are being considered and investigated in the context human-machine teaming for the ATTRACTOR design reference mission (DRM) of Search and Rescue or (more generally) intelligence, surveillance, and reconnaissance (ISR). The first of these investigations, the Human Informed Natural-language GANs Evaluation (HINGE) data collection effort, is aimed at building an image description database to train a Generative Adversarial Network (GAN). In addition to building an image description database, the HMI team was interested if, and how, modality (spoken vs. written) affects different aspects of the image description given. The results will be analyzed to better inform the designing of an interface for mission planning.

Generative Adversarial Network (GAN)↗