Search NASA⌕ Search

SEARCH · Search NASA

Results for “Provable security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

Provable Security and Resilience in Critical Infrastructure – Next Steps

With the conclusion of the Laboratory Directed Research and Development (LDRD) project on Provable Security and Resilience (PSaR) in Critical Infrastructure, we present forward-looking technical concepts and strategies that build on the project’s outcomes and INL’s long-standing expertise in infrastructure protection. The challenge is to protect critical infrastructure and functions much more efficiently at scale than capable adversaries can attack at scale. After summarizing progress and ongoing work we’ll discuss what are the challenges that remain and what are new/emerging technologies, strategies, and processes to meet those challenges. Finally, we’ll layout concepts that integrate with other protection work in the coming year and beyond. For example, building secure function-specific platforms based on the seL4 microkernel, and considering the successes of Cyber-Informed Engineering as a model for engage, collaboration, and adoption. We look forward to your feedback and collaboration as we refine and expand this vision.

97 - MATHEMATICS AND COMPUTING↗

Formal Methods for Provably Secure Software and Firmware

This project addresses a gap observed in verifying the programming in embedded devices used in international arms control: namely verifying that embedded programming in an arms control device does exactly what it is supposed to do, no more and no less, every time without fail, and without disclosing unauthorized information accidentally or intentionally. In critical military, aerospace, and industrial safety systems this problem is sometimes addressed using formal methods (FM). This multi-year project seeks to identify formal methods toolsets useable in arms control regimes, with emphasis on applicability, ease of use, long term availability, and support.

formal methods, Arms Control Verification↗

Towards Provable Security in Industrial Control Systems Via Dynamic Protocol Attestation

Industrial control systems (ICSs) increasingly rely on digital technologies vulnerable to cyber attacks. Cyber attackers can infiltrate ICSs and execute malicious actions. Individually, each action seems innocuous. But taken together, they cause the system to enter an unsafe state. These attacks have resulted in dramatic consequences such as physical damage, economic loss, and environmental catastrophes. This paper introduces a methodology that restricts actions using protocols. These protocols only allow safe actions to execute. Protocols are written in a domain specific language we have embedded in an interactive theorem prover (ITP). The ITP enables formal, machine-checked proofs to ensure protocols maintain safety properties. We use dynamic attestation to ensure ICSs conform to their protocol even if an adversary compromises a component. Since protocol conformance prevents unsafe actions, the previously mentioned cyber attacks become impossible. We demonstrate the effectiveness of our methodology using an example from the Fischertechnik Industry 4.0 platform. We measure dynamic attestation's impact on latency and throughput. Our approach is a starting point for studying how to combine formal methods and protocol design to thwart attacks intended to cripple ICSs.

97 MATHEMATICS AND COMPUTING↗

Digital Assurance for High Consequence Systems: 2024 Mission Campaign White Paper

This Sandia National Laboratories Mission Campaign (MC) seeks to create the technical basis that allows national leaders to efficiently assess and manage the digital assurance of high consequence systems. We will call for transformative research that enables efficient (1) development of provably secure systems and secure integration of untrusted products, (2) intelligent threat mitigation, and (3) digital risk-informed engineering trade-offs. Ultimately, this MC will impact multiple national security missions; it will develop an informed Digital Assurance for High Consequence Systems (DAHCS) community and expand Sandia partnerships to build this national capability.

97 MATHEMATICS AND COMPUTING↗

Exploring Applied Cryptosystems to Formally Verify Security in Cyber-Physical Systems

This project aims to evaluate RSA as a method for public-key encryption for cyber-physical systems (CPS). As technology advances, cyber attacks are increasing, and with them, the need for cybersecurity advances; the average cost for cybercrime in the world was estimated at $6 trillion in 2021. A public-key cryptosystem that has been around since 1977, RSA has recently garnered some critiques for its fragility, computational cost, and lazy implementation. In this project I will review the mathematical derivation of RSA, analyze the practical implications of such mathematical framework for the security of RSA, and propose a formal methods based approach to verify encryption schemes for CPS.

97 MATHEMATICS AND COMPUTING↗

Secure System Composition and Type Checking using Cryptographic Proofs [Slides]

By using zkSNARKs to prove that values have specific dependent types, it is possible to provably assure compatibility and correctness without revealing sensitive information and extend our trusted computing base well beyond our own system. The approach we developed expands the scope of what non-interactive zero-knowledge proofs can capture to include properties about both the execution and correctness of programs.

97 MATHEMATICS AND COMPUTING↗