Search NASA⌕ Search

SEARCH · Search NASA

Results for “Authentication”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Streaming authentication and multi-level security for communications networks using quantum cryptography

Message authenticators for quantum-secured communications facilitate low-latency authentication with assurances of security. Low-latency message authenticators are especially valuable in infrastructure systems where security and latency constraints are difficult to satisfy with conventional non-quantum cryptography. For example, a message transmitter receives a message and derives an authentication tag for the message based at least in part on an authenticator that uses one or more quantum keys. The message transmitter outputs the message and its authentication tag. A message receiver receives a message and authentication tag for the message. The message receiver derives a comparison tag for the message based at least in part on an authenticator that uses one or more quantum keys. The message receiver checks whether the message is authentic based on a comparison of the authentication tag and the comparison tag. In example implementations, the authenticator uses stream-wise cyclic redundancy code operations.

Hughes, Richard J.↗

Optical authentication of images

Systems and methods performed for generating authentication information for an image using optical computing are provided. When a user takes a photo of an object, an optical authentication system receives light reflected and/or emitted from the object. The system also receives a random key from an authentication server. The system converts the received light to plenoptic data and uploads it to the authentication server. In addition, the system generates an optical hash of the received light using the random key, converts the generated optical hash to a digital optical hash, and uploads the digital optical hash to the authentication server. When the authentication server receives the upload, it verifies whether the time of the upload is within a certain threshold time from the sending of the random key and whether the digital optical hash was generated from the same light as the plenoptic data.

97 MATHEMATICS AND COMPUTING↗

Optical authentication of images

Systems and methods performed for generating authentication information for an image using optical computing are provided. When a user takes a photo of an object, an optical authentication system receives light reflected and/or emitted from the object. The system also receives a random key from an authentication server. The system converts the received light to plenoptic data and uploads it to the authentication server. In addition, the system generates an optical hash of the received light using the random key, converts the generated optical hash to a digital optical hash, and uploads the digital optical hash to the authentication server. When the authentication server receives the upload, it verifies whether the time of the upload is within a certain threshold time from the sending of the random key and whether the digital optical hash was generated from the same light as the plenoptic data.

Murialdo, Maxwell R.↗

Adoption of a token-based authentication model for the CMS Submission Infrastructure

The CMS Submission Infrastructure (SI) is the main computing resource provisioning system for CMS workloads. A number of HTCondor pools are employed to manage this infrastructure, which aggregates geographically distributed resources from the WLCG and other providers. Historically, the model of authentication among the diverse components of this infrastructure has relied on the Grid Security Infrastructure (GSI), based on identities and X509 certificates. In contrast, commonly used modern authentication standards are based on capabilities and tokens. The WLCG has identified this trend and aims at a transparent replacement of GSI for all its workload management, data transfer and storage access operations, to be completed during the current LHC Run 3. As part of this effort, and within the context of CMS computing, the Submission Infrastructure group is in the process of phasing out the GSI part of its authentication layers, in favor of IDTokens and Scitokens. The use of tokens is already well integrated into the HTCondor Software Suite, which has allowed us to fully migrate the authentication between internal components of SI. Additionally, recent versions of the HTCondor-CE support tokens as well, enabling CMS resource requests to Grid sites employing this CE technology to be granted by means of token exchange. After a rollout campaign to sites, successfully completed by the third quarter of 2022, the totality of HTCondor CEs in use by CMS are already receiving Scitoken-based pilot jobs. On the ARC CE side, a parallel campaign was launched to foster the adoption of the REST interface at CMS sites (required to enable token-based job submission via HTCondor-G), which is nearing completion as well. In this contribution, the newly adopted authentication model will be described. We will then report on the migration status and final steps towards complete GSI phase out in the CMS SI.

Pérez-Calero Yzquierdo, Antonio↗

Precoder Design for Physical-Layer Security and Authentication in Massive MIMO UAV Communications

Supporting reliable and seamless wireless connectivity for unmanned aerial vehicles (UAVs) has recently become a critical requirement to enable various different use cases of UAVs. Due to their widespread deployment footprint, cellular networks can support beyond visual line of sight (BVLOS) communications for UAVs. In this paper, we consider cellular connected UAVs (C-UAVs) that are served by massive multiple input-multiple-output (MIMO) links to extend coverage range, while also improving physical layer security and authentication. Here, we consider Rician channel and propose a novel linear precoder design for transmitting data and artificial noise (AN). We derive the closed-form expression of the ergodic secrecy rate of CUAVs for both conventional and proposed precoder designs. In addition, we obtain the optimal power splitting factor that divides the power between data and AN by asymptotic analysis. Then, we apply the proposed precoder design in the fingerprint embedding authentication framework, where the goal is to minimize the probability of detection of the authentication tag at an eavesdropper. In simulation results, we show the superiority of the proposed precoder in both secrecy rate and the authentication probability considering moderate and large number of antenna massive MIMO scenarios.

99 GENERAL AND MISCELLANEOUS↗

Advanced Reactor Control Systems Authentication Methods and Recommendations

In the dynamic landscape of Operational Technology (OT), and specifically the emerging landscape for Advanced Reactors, the establishment of trust between digital assets emerges as a challenge for cybersecurity modernization. This report reviews existing approaches to authentication in Enterprise environments, and proposed methods for authentication in OT, and analyzes each for its applicability to future Advanced Reactor digital networks. Principles of authentication ranging from underlying cryptographic mechanisms to trust authorities are evaluated through the lens of OT. These facets emphasize the importance of mutual authentication in real-time environments, enabling a paradigm shift from the current approach of strong boundaries to a more malleable network that allows for flexible operation. This work finds that there is a need for evaluation and decision making by industry stakeholders, but current technologies and approaches can be adapted to fit needs and risk tolerances.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

PUF-Based Two-Factor Authentication Protocol for Securing the Power Grid Against Insider Threat

Recent advances in smart grid technologies have enabled additional distributed control paradigms that allow more efficient and reliable operation. However, this creates new security concerns for the grid, such as attackers using spoofed grid control devices to generate false measurements. This paper introduces a two-factor authentication protocol leveraging standard public-key cryptography as one authentication factor and a hardware-based fingerprint, known as a Physical Unclonable Function, as a second authentication factor. This protocol incurs a small overhead and prevents cyber-attacks even when an adversary is able to compromise the cryptographic keys stored in the non-volatile memory of an intelligent control device.

42 ENGINEERING↗

Clean Energy Cybersecurity Accelerator Cohort 1: Authentication and Authorization

In the 2023 National Cybersecurity Strategy, the Biden-Harris Administration defines the need for a "defensible, resilient digital ecosystem where it is costlier to attack systems than defend them." The strategy cites the Clean Energy Cybersecurity Accelerator (CECA) as an exemplary effort to bolster the security and resilience of clean energy generation. These efforts help "secure the clean energy grid of the future and [generate] security best practices that extend to other critical infrastructure sectors" and promise broad and far-reaching impacts to bridge the capabilities of private industry and the needs of energy production. Cohort 1 of CECA launched in the fall of 2022 with a focus on solutions that provide strong authentication and authorization for industrial control systems to mitigate attacks on the energy grid. Authentication and authorization verify that the identity (authentication) and permissions (authorization) of a user or device are aligned with their assigned roles. Weaknesses in either can have serious repercussions. To assess the strength of Cohort 1's solutions, CECA devised threat scenarios grounded in historical precedents: the CECA team reviewed exploits from real-world case studies of state-sponsored actors to match the assessment's attack paths and targets. Cohort 1 results provided the energy industry, product vendors, and related agencies valuable insights into the efficacy and applicability of solutions in common system configurations under realistic threat scenarios. The results of the assessment highlight points for interrogation and improvement in subsequent technology iterations. CECA's evaluations are part of an ongoing conversation and collaboration to bolster U.S. cyber resilience against adversaries today and in the future.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Highlighting the Importance of Authentic Reference Chemicals in the Unambiguous Identification of Unknowns during Routine Sample Analysis─An OPCW Proficiency Test Case

The unequivocal identification of unknown chemicals during routine sample analysis is a constant occurrence in the field of analytical chemistry. The process can be painstakingly tedious, particularly in situations where a tentatively identified unknown may possess isomeric counterparts yielding identical accurate mass values and very similar mass spectra. In this work, we present the experimental process involved in the correct identification of 1,4-oxathiane 4,4-dioxide and differentiation from its constitutional isomer, 2-hydroxyethyl vinyl sulfone, when present in a silica gel matrix featured in the 54th Environmental Organisation for the Prohibition of Chemical Weapons (OPCW) proficiency test. After discovering that the library-generated mass spectrum for 2-hydroxyethyl vinyl sulfone in a preliminary gas chromatography–mass spectrometry (GC-MS) analysis did not match the one from an authentic reference chemical, we embarked on an unknown structure determination campaign involving GC-MS, liquid chromatography-tandem mass spectrometry (LC-MS-MS), and nuclear magnetic resonance (NMR) spectroscopy. All of the information obtained, coupled to the synthesis of an authentic reference chemical, was used to determine the identity of the unknown as 1,4-oxathiane 4,4-dioxide. The process described in this work highlights the important role played by authentic reference chemicals in the identification of unknown chemicals during routine sample analysis.

Chemistry↗

Non-invasive authentication of mail packages using nuclear quadrupole resonance spectroscopy

The international postal network is one of the most widely used methods for correspondence throughout the world. Most postal traffic across the globe consists of legitimate interpersonal, business-consumer, and business-business communications. However, the global postal system is also utilized for criminal activity. In particular, it is often utilized to ship and distribute contraband, including illegal psychoactive drugs such as fentanyl and heroin, to consumers. Existing technological solutions are capable of identifying synthetic opioids and other illegal drugs within packages, but are accompanied by several disadvantages that make them unsuitable for large-scale authentication of international mail traffic. This paper presents a novel method for non-invasive authentication of mail packages that overcomes these challenges. The approach uses nuclear quadrupole resonance (NQR) spectroscopy to detect and quantify the presence of known active pharmaceutical ingredients (APIs) within the package. It has been experimentally demonstrated using a bench top prototype. Test results from a variety of package types demonstrate the effectiveness of the proposed authentication approach.

42 ENGINEERING↗

Systems and methods for distributed authentication of devices

A lightweight, fast, and reliable authentication mechanism compatible with the 5G D2D ProSe standard mechanisms is provided. A distributed authentication with a delegation-based scheme avoids repeated access to the 5G core network key management functions. Hence, a legitimate user equipment device (e.g., a drone) is authorized by the cellular network (e.g., 5G cellular network) via offering a proxy signature to authenticate itself to other drones. Test results demonstrate that the protocol is lightweight and reliable.

Akkaya, Kemal↗

Authentication of smart grid communications using quantum key distribution

Smart grid solutions enable utilities and customers to better monitor and control energy use via information and communications technology. Information technology is intended to improve the future electric grid’s reliability, efficiency, and sustainability by implementing advanced monitoring and control systems. However, leveraging modern communications systems also makes the grid vulnerable to cyberattacks. Here we report the first use of quantum key distribution (QKD) keys in the authentication of smart grid communications. In particular, we make such demonstration on a deployed electric utility fiber network. The developed method was prototyped in a software package to manage and utilize cryptographic keys to authenticate machine-to-machine communications used for supervisory control and data acquisition (SCADA). This demonstration showcases the feasibility of using QKD to improve the security of critical infrastructure, including future distributed energy resources (DERs), such as energy storage.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A Novel Authentication Management for the Data Security of Smart Grid

Bidirectional wireless communication is employed in various smart grid components such as smart meters and control and monitoring applications where security is vital. The Trusted Third Party (TTP) and wireless connectivity between the smart meter and the third party in the key management-based encryption techniques for the smart grid are expected to be totally trustworthy and dependable. In a wired/wireless medium, however, a man-in-the-middle may seek to disrupt, monitor and manipulate the network, or simply execute a replay attack, revealing its vulnerability. Recognizing this, this study presents a novel authentication management (model) comprised of two layer security schema. The first layer implements an efficient novel encryption method for secure data exchange between meters and control center with the help of two partially trusted simple servers (constitutes the TTP). In this setting, one server handles the data encryption between the meter and control center/central database, and the other server administers the random sequence of data transmission. The second layer monitors and verifies exchanged data packets among smart meters. It detects abnormal packets from suspicious sources. To implement this node-to-node authentication, One class support vector machine algorithm is proposed which takes advantages of the location information as well as the data transmission history (node identification, packet size, and data transmission frequency). This schema secures data communication, and imposes a comprehensive privacy throughout the system without considerably extending the complexity of the conventional key management scheme.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Active High Assurance Authentication Protocol (AHAAP)

The AHAAP Maturation Project involves maturation and evaluation of a patented zero-trust tamper-resistant high-assurance session-less dynamic and active device authentication protocol that simultaneously authenticates identity and provides integrity verification in a single step, substantially reducing the risk of cyberattack, and eliminating the need for costly and complex conventional communication security systems requirements (i.e., cryptography, Public Key Infrastructure (PKI), and key management). These cybersecurity attributes of the technology must be preserved when applying the technology to different cybersecurity solutions, including Command & Control (C&C), Over-the-Air (OTA) update, Common Access Card (CAC), and distributed energy resource (DER) implementations, among others. The technology research objective is to test and verify that the cybersecurity attributes of the technology are not degraded in different cybersecurity applications. The primary technology development objective is to build minimum viable products to demonstrate the technology addresses today’s cybersecurity threats so that prospective investors, strategic partners, regulatory agencies, and commercial customers can interact with and assess the protection assured by the technology. The AHAAP Maturation Project goal is to develop, test, and validate one or more AHAAP implementations. The AHAAP Maturation Project tasks are: (i) engineer AHAAP implementation software, (ii) build a functional prototype that implements the AHAAP software for demonstration, testing, analysis, and evaluation purposes, and (iii) generate a report detailing the results of the AHAAP C&C software and hardware implementation. The final project deliverables are: (i) AHAAP software implementation and prototype, (ii) a report from Sandia National Laboratories detailing the results of the AHAAP implementations.

97 MATHEMATICS AND COMPUTING↗

Fermilab s Transition to Token Authentication

Fermilab is the first High Energy Physics institution to transition from X.509 user certificates to authentication tokens in production systems. All of the experiments that Fermilab hosts are now using JSON Web Token (JWT) access tokens in their grid jobs. Many software components have been either updated or created for this transition, and most of the software is available to others as open source. The tokens are defined using the WLCG Common JWT Profile. Token attributes for all the tokens are stored in the Fermilab FERRY system which generates the configuration for the CILogon token issuer. High security-value refresh tokens are stored in Hashicorp Vault configured by htvault-config, and JWT access tokens are requested by the htgettoken client through its integration with HTCondor. The Fermilab job submission system jobsub was redesigned to be a lightweight wrapper around HTCondor. For automated job submissions a managed tokens service was created to reduce duplication of effort and knowledge of how to securely keep tokens active. The existing Fermilab file transfer tool ifdh was updated to work seamlessly with tokens, as well as the Fermilab POMS (Production Operations Management System) which is used to manage automatic job submission and the RCDS (Rapid Code Distribution System) which is used to distribute analysis code via the CernVM FileSystem. The dCache storage system was reconfigured to accept tokens for authentication in place of X.509 proxy certificates. As some services and sites have not yet implemented token support, proxy certificates are still sent with jobs for backwards compatibility but some experiments are beginning to transition to stop using them. There have been some glitches and learning curve issues but in general the system has been performing well and is being improved as operational problems are addressed.

Dykstra, David↗

Systems and methods for quantum optical device authentication

Quantum optical device authentication technologies are described herein. A first device includes an optical transmitter transmits a plurality of pulses to an optical receiver included on a second device. The optical pulses each have one of two non-orthogonal optical states. The optical receiver measures each of the pulses and the second device records a measured value of the optical state of each pulse. Subsequently, the second device transmits the measured values of the optical states of the pulses to the first device. The first device outputs an indication of whether the second device is authenticated based upon the measured values received from the second device and the optical states of the pulses transmitted by the optical transmitter.

Soh, Daniel Beom Soo↗

Secure authentication using recurrent neural networks

A computer-implemented method of user authentication is provided. The method comprises combining, by a computer system, a user recurrent neural network with a system recurrent neural network to form a unique combined recurrent neural network. The user recurrent neural network is configured to generate a unique user key, and the system recurrent neural network is configured to generate a system key. The computer system inputs a predetermined input into the combined recurrent neural network, and the combined recurrent neural network generates a unique combined key from the input, wherein the combined key differs from both the user key and system key. The computer system then associates the combined key with a unique access authorization to authenticate a user.

Aimone, James Bradley↗

Methods and systems for authenticating identity

Systems and methods are disclosed that provide for secure communications between a user device and an authentication system. The systems and methods create a dynamic identification for the device that is stored in both the device and authentication system.

Choi, Sung Nam↗