Search NASASearch

SEARCH · Search NASA

Results for “Utility Cybersecurity”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

Quantum Technologies for UAS (QTech)

Harness the power of quantum technologies to assure the availability of UAS communications against disruptions. Make use of quantum computing (e.g. quantum optimization) and quantum communication (e.g. quantum key distribution) to address the availability cybersecurity challenge. Our approach is three-fold: (1) Utilize quantum optimization algorithms to design robust network with routing redundancy that can respond adaptively to dynamically changing real-time environment and disruptions, (2) Utilize quantum optimization algorithms resource allocation for detection, localization, and tracking of mobile communication disruption agents, (3) Utilize quantum key distribution (QKD) to execute secure key sharing in high data rate optical communication and/or anti-jamming protocols for secure RF communication.

Quantum Computing

Applying a Space-Based Security Recovery Scheme for Critical Homeland Security Cyberinfrastructure Utilizing the NASA Tracking and Data Relay (TDRS) Based Space Network

Protection of the national infrastructure is a high priority for cybersecurity of the homeland. Critical infrastructure such as the national power grid, commercial financial networks, and communications networks have been successfully invaded and re-invaded from foreign and domestic attackers. The ability to re-establish authentication and confidentiality of the network participants via secure channels that have not been compromised would be an important countermeasure to compromise of our critical network infrastructure. This paper describes a concept of operations by which the NASA Tracking and Data Relay (TDRS) constellation of spacecraft in conjunction with the White Sands Complex (WSC) Ground Station host a security recovery system for re-establishing secure network communications in the event of a national or regional cyberattack. Users would perform security and network restoral functions via a Broadcast Satellite Service (BSS) from the TDRS constellation. The BSS enrollment only requires that each network location have a receive antenna and satellite receiver. This would be no more complex than setting up a DIRECTTV-like receiver at each network location with separate network connectivity. A GEO BSS would allow a mass re-enrollment of network nodes (up to nationwide) simultaneously depending upon downlink characteristics. This paper details the spectrum requirements, link budget, notional assets and communications requirements for the scheme. It describes the architecture of such a system and the manner in which it leverages off of the existing secure infrastructure which is already in place and managed by the NASAGSFC Space Network Project.

Cybersecurity

Developing a Cybersecurity Architecture for Extensible Traffic Management (xTM)

This paper explores the development of a cybersecurity architecture tailored for Extensible Traffic Management (xTM) to address emerging challenges in managing diverse aerial vehicles within the National Airspace System (NAS). Driven by technological advances and the rise of uncrewed aerial systems (UAS), urban air mobility (UAM), and high-altitude traffic (ETM), the NAS is undergoing a paradigm shift. Traditional air traffic management, reliant on traditional Federal Aviation Administration (FAA) control, will give way to decentralized coordination among autonomous and semi-autonomous systems. The proposed xTM Security Architecture, designed as a high-level framework, focuses on ensuring the confidentiality, integrity, and availability of data and operations in this evolving ecosystem. Utilizing threat modeling, the research identifies potential risks across key flight phases, operations and use cases to offer security control recommendations. Key objectives include analyzing interactions between novel airspace entrants and existing NAS traffic, cataloging vulnerabilities, and developing mitigative strategies to ensure safety, operational stability, and secure data exchanges. This research lays the groundwork for regulatory and industry adaptation, providing critical insights into managing cybersecurity risks in this complex, multi-domain environment.

UAM

The Mars 2020 Ground Data System Architecture

The Mars 2020 Mission’s primary objective is to collect 20 geographically unique samples during its prime mission of one and a quarter Martian years, or just over 2 Earth years. Mission planners determined the project needed to develop a system that would enable the operations team to analyze engineering and science data, make science decisions, select viable rover targets at a millimeter resolution and validate an uplink bundle for a car sized rover with more complex science instruments than any previous Mars surface mission. All this had to be done within a five hour time frame. Doing this with a small team would be a challenge, but this had to be accomplished by a large team of engineers and scientists located across North America and Europe. Achieving this level of operational efficiency was unheard of in the prime mission. In addition, the mission had another set of requirements that had nothing to do with surface operations; the Mars 2020 Ground Data System (GDS) was also expected to comply with a new set of security requirements to keep up with the ever changing cybersecurity landscape. The Mars 2020 Ground Data System (GDS) is a re-architected version of the Mars Science Laboratory GDS. The primary goal was to integrate the lessons learned from previous Mars surface missions, accommodate a set of new requirements and capabilities required to ensure mission success, and comply with a new set of cybersecurity controls. The new architecture includes several unique qualities including a data lake, language-agnostic system-wide event-based operations, containerization, automated deployment, network segmentation, infrastructure-as-code, API-driven interfaces, and the first Mars surface GDS to operate primarily in the cloud. The new architecture enabled greater access to the system’s data, tighter integration with the operations team, and a higher level of traceability. The availability of the data also enabled a new set of capabilities previously not possible on surface missions. These new capabilities include an autonomous data to information, pipeline for downlink analysis, horizontal scaling of science data processing capabilities, autonomous round trip data tracking of science and engineering data, integration of flight system state into the tactical planning cycle, high fidelity targeting utilizing kinematic data, and hierarchical image and 3d meshes data representations. This paper will introduce the requirements for the Mars 2020 Mission, the heritage architecture, and the rationale for the changes to achieve the new architecture. The paper will continue to describe the fundamental changes made to the GDS architecture, how these changes enabled a more tightly integrated GDS, and the new capabilities that were enabled by the new architecture. The paper will conclude with the lessons learned from the process of rearchitecting a heritage GDS system and from the first 200 days of operations supporting over 800 users from around the world.

Lopez-Roig, Reynaldo

Cyber Resiliency and the Implementation of a Host-Based Intrusion Detection System in an Urban Air Mobility Environment

With the growth in Urban Air Mobility systems and the increasing reliance on interconnected technologies, ensuring the security of these complex components has become critical. As cities evolve into smart urban centers, the vulnerability to cyber threats escalates, possibly endangering citizens safety and the efficiency of transportation networks.In response to these challenges, this paper presents a study on the need for cyber resilient techniques within future air traffic environments. It will pay specific attention to the implementation of a Host-Based Intrusion Detection System (HIDS) utilizing Atomic OSSEC software, tailored specifically to a NASA simulation of an UrbanAirMobility environments’ unique demands. Further, this study seeks to outline the rational for NASA’s recommendation for a HIDS in such environments. It explores the design, development, and deployment of the proposed HIDS, focusing on its adaptability to monitor the hybrid nature of the Urban Air Mobility environment. Leveraging machine learning algorithms and anomaly detection techniques, the HIDS is equipped to continuously monitor and analyze the behavior of individual host systems, vehicles, and devices, thereby providing a proactive approach to threat detection. Implementing a HIDS is a pivotal strategy for enhancing cyber resiliency, as it gives an organization granular visibility into internal system activities, enables rapid detection and response to anomalous behavior and cyber threats, and fortifies the organizations overall cybersecurity posture. Finally, this study aims to provide recommendations and include learned takeaways that the Urban Air Mobility industry should consider. In brief, this paper highlights the significance of host-based intrusion detection in UrbanAirMobility environments and underscores the necessity of tailored security solutions to safeguard against emerging cyber threats.

UAM

NASA Aeronautics Research Mission Directorate System Security Engineering Approaches

System security engineering (SSE) is a set of formal engineering methods and is considered a subset of systems engineering. It is a relatively new development in systems engineering with the initial NIST (National Institute of Standards) standard published in November of 2016 with updates in 2018, and 2022. The guiding principles in our methodology are based in NIST Special Publication 800-160 Vol. 1 “Systems Security Engineering: Considerations For A Multidisciplinary Approach In The Engineering Of Trustworthy Secure Systems” and integrate methodologies from common IT (Information Technology) threat modeling approaches utilizing MBSE (Model-Based Systems Engineering). The presentation will discuss how our teams utilize SSE and MBSE (Model-Based Systems Engineering) to develop secure architectures for systems under development in our NASA aeronautics research environment. This includes the activities to develop Protection Needs (PN) that, in turn result in security requirements in the design context and policies for the future state operational context for system protection. The process of applying SSE to analyze project architectures and ConOps (Concept of Operations) is intended to ensure the transferred research is both secure and securable in a “real-world” setting.

Systems Security Engineering

The State of CryptoLib – The Open-Source Satellite Cryptography Library

What state would the world be in if all internet traffic was unencrypted? Imagine an alternate universe where you can plug a packet sniffing device into your home internet and capture the web traffic of the entire world. It seems obvious that this scenario is less than desirable. If we would not allow this for the internet, why would we allow this in the space domain? With the advent of open-source ground stations, commercial off the shelf hardware, and ground stations as a service, the barrier to entry for space communications is rapidly lowering. New players enter the space realm everydayevery day, and the presence of tools to allow apprentice evildoers the ability to exploit satellite communications is on the horizon. Not only are legacy missions at risk, but future missions are as well - particularly lower budget science missions with more stringent sciencesize, weight, and power constraints. that may find it difficult to utilize hardware-based encryption solutions. In terms of Civilian Aerospace, NASA Standard 1006 generally directs that missions "shall protect the command stack with encryption that meets or exceeds Federal Information Processing Standards (FIPS) 140". Fortunately, the Consultative Committee for Space Data Systems (CCSDS) has published an international standard on Space Data Link Security. The combination of these two forces has resulted in CryptoLib - an open-source, C-based, encryption library that aims to be CCSDS SDLS compliant. CryptoLib is designed to support smaller missions on a tight budget that may be subject to the more stringent command link encryption requirements. Additionally, CryptoLib serves as an underpinning in JPL's Key Management & Cryptography (KMC) suite and is also designed to function as a 'drop-in' for smaller missions. CryptoLib is in active development and currently provides Telecommand (TC), Telemetry (TM), and Advanced Orbiting Systems (AOS) encryption and decryption capabilities with a variety of encryption and authentication schemes. This presentation will report the latest features, current status, and future plans for CryptoLib.

open-source encryption

The State of Cryptolib – The Open-Source Satellite Cryptography Library

What state would the world be in if all internet traffic was unencrypted? Imagine an alternate universe where you can plug a packet sniffing device into your home internet and capture the web traffic of the entire world. It seems obvious that this scenario is less than desirable. If we would not allow this for the internet, why would we allow this in the space domain? With the advent of open-source ground stations, commercial off the shelf hardware, and ground stations as a service, the barrier to entry for space communications is rapidly lowering. New players enter the space realm everydayevery day, and the presence of tools to allow apprentice evildoers the ability to exploit satellite communications is on the horizon. Not only are legacy missions at risk, but future missions are as well - particularly lower budget science missions with more stringent sciencesize, weight, and power constraints. that may find it difficult to utilize hardware-based encryption solutions. In terms of Civilian Aerospace, NASA Standard 1006 generally directs that missions "shall protect the command stack with encryption that meets or exceeds Federal Information Processing Standards (FIPS) 140". Fortunately, the Consultative Committee for Space Data Systems (CCSDS) has published an international standard on Space Data Link Security. The combination of these two forces has resulted in CryptoLib - an open-source, C-based, encryption library that aims to be CCSDS SDLS compliant. CryptoLib is designed to support smaller missions on a tight budget that may be subject to the more stringent command link encryption requirements. Additionally, CryptoLib serves as an underpinning in JPL's Key Management & Cryptography (KMC) suite and is also designed to function as a 'drop-in' for smaller missions. CryptoLib is in active development and currently provides Telecommand (TC), Telemetry (TM), and Advanced Orbiting Systems (AOS) encryption and decryption capabilities with a variety of encryption and authentication schemes. This presentation will report the latest features, current status, and future plans for CryptoLib.

open-source encryption

Quasi-Wireless Capacitive Power Transfer with Secure Data Acquisition for Robotic Systems in Space Infrastructure

Space exploration is dependent on robotic systems that utilize end-effectors to collect samples, probe surfaces, and manipulate objects. These systems can rarely be designed to do all three, forcing engineers to make tradeoffs based on the mission parameters - i.e. should the robotic appendage have a claw, drill, or shovel, and which would be best suited for the mission? Additionally, as more industrial and government entities partake in space exploration, data protection is needed in transit and at rest. To address these challenges, we present a first-of-its- kind robotic linkage that has no wiring between the joints. Instead, quasi-wireless capacitive (QWiC) power transfer is used to send energy over the robot’s chassis without a return wire. This enables the system to be completely modular through the use of single-contact permanent magnet connections, allowing rapid alterations in joint kinematics and/or the changing of end-effectors. For collecting sensor data from the robotic arm and to send remote commands to it, we use a Supervisory Control and Data Acquisition (SCADA) system. Data transmission relies on MQTT and OPC UA communication protocols with encryption. The SCADA server logs and archives sensor data and provides the functionality for authorized users to send remote commands from SCADA client(s) to motors. A SCADA client can be any of the web browsers that connects to a server via a secure communication channel using SSL protocol. Furthermore, as an extra data protection mechanism, we inject noise to the sensor data traffic, which obfuscates the timing of sensor data packets and adds confusion about which data packet represents which motor.

wireless sensor networks