Search NASASearch

SEARCH · Search NASA

Results for “authentication”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Highlighting the Importance of Authentic Reference Chemicals in the Unambiguous Identification of Unknowns during Routine Sample Analysis─An OPCW Proficiency Test Case

The unequivocal identification of unknown chemicals during routine sample analysis is a constant occurrence in the field of analytical chemistry. The process can be painstakingly tedious, particularly in situations where a tentatively identified unknown may possess isomeric counterparts yielding identical accurate mass values and very similar mass spectra. In this work, we present the experimental process involved in the correct identification of 1,4-oxathiane 4,4-dioxide and differentiation from its constitutional isomer, 2-hydroxyethyl vinyl sulfone, when present in a silica gel matrix featured in the 54th Environmental Organisation for the Prohibition of Chemical Weapons (OPCW) proficiency test. After discovering that the library-generated mass spectrum for 2-hydroxyethyl vinyl sulfone in a preliminary gas chromatography–mass spectrometry (GC-MS) analysis did not match the one from an authentic reference chemical, we embarked on an unknown structure determination campaign involving GC-MS, liquid chromatography-tandem mass spectrometry (LC-MS-MS), and nuclear magnetic resonance (NMR) spectroscopy. All of the information obtained, coupled to the synthesis of an authentic reference chemical, was used to determine the identity of the unknown as 1,4-oxathiane 4,4-dioxide. The process described in this work highlights the important role played by authentic reference chemicals in the identification of unknown chemicals during routine sample analysis.

Chemistry

Fermilab s Transition to Token Authentication

Fermilab is the first High Energy Physics institution to transition from X.509 user certificates to authentication tokens in production systems. All of the experiments that Fermilab hosts are now using JSON Web Token (JWT) access tokens in their grid jobs. Many software components have been either updated or created for this transition, and most of the software is available to others as open source. The tokens are defined using the WLCG Common JWT Profile. Token attributes for all the tokens are stored in the Fermilab FERRY system which generates the configuration for the CILogon token issuer. High security-value refresh tokens are stored in Hashicorp Vault configured by htvault-config, and JWT access tokens are requested by the htgettoken client through its integration with HTCondor. The Fermilab job submission system jobsub was redesigned to be a lightweight wrapper around HTCondor. For automated job submissions a managed tokens service was created to reduce duplication of effort and knowledge of how to securely keep tokens active. The existing Fermilab file transfer tool ifdh was updated to work seamlessly with tokens, as well as the Fermilab POMS (Production Operations Management System) which is used to manage automatic job submission and the RCDS (Rapid Code Distribution System) which is used to distribute analysis code via the CernVM FileSystem. The dCache storage system was reconfigured to accept tokens for authentication in place of X.509 proxy certificates. As some services and sites have not yet implemented token support, proxy certificates are still sent with jobs for backwards compatibility but some experiments are beginning to transition to stop using them. There have been some glitches and learning curve issues but in general the system has been performing well and is being improved as operational problems are addressed.

Dykstra, David

Systems, devices, and methods for authenticating millimeter wave devices

Systems, devices, and methods are described for millimeter wave device authentication. A system may include one or more access points. Each access point of the one or more access points is configured to extract, from one or more beam patterns generated via a client device, a beam feature associated with the client device. Each access point may also be configured to transmit the beam feature. The system may also include a server communicatively coupled to the one or more access points and including a database for storing known beam features. The server may be configured to receive the beam feature associated with the client device from at least one access point of the one or more access points. Also, the server may be configured to authenticate the client device in response to the received beam feature matching a known beam feature stored in the at least one database.

Bhuyan, Arupjyoti

Fermilab's Transition to Token Authentication

Fermilab is the first High Energy Physics institution to transition from X.509 user certificates to authentication tokens in production systems. All the experiments that Fermilab hosts are now using JSON Web Token (JWT) access tokens in their grid jobs. Many software components have been either updated or created for this transition, and most of the software is available to others as open source. The tokens are defined using the WLCG Common JWT Profile. Token attributes for all the tokens are stored in the Fermilab FERRY system which generates the configuration for the CILogon token issuer. High security-value refresh tokens are stored in Hashicorp Vault configured by htvault-config, and JWT access tokens are requested by the htgettoken client through its integration with HTCondor. The Fermilab job submission system jobsub was redesigned to be a lightweight wrapper around HTCondor. The grid workload management system GlideinWMS which is also based on HTCondor was updated to use tokens for pilot job submission. For automated job submissions a managed tokens service was created to reduce duplication of effort and knowledge of how to securely keep tokens active. The existing Fermilab file transfer tool ifdh was updated to work seamlessly with tokens, as well as the Fermilab POMS (Production Operations Management System) which is used to manage automatic job submission and the RCDS (Rapid Code Distribution System) which is used to distribute analysis code via the CernVM FileSystem. The dCache storage system was reconfigured to accept tokens for authentication in place of X.509 proxy certificates. As some services and sites have not yet implemented token support, proxy certificates are still sent with jobs for backwards compatibility, but some experiments are beginning to transition to stop using them.

Dykstra, Dave [Fermilab] (ORCID:0000000326539015)

Simulation of a Wireless Authentication Protocol

Abstract—A wireless authentication protocol that employs timeslots and associated frequency-channels (APEC) is simulated using Python as the simulation environment and implemented into radio hardware as a proof of concept. The APEC protocol does not rely on the use of challenge-response, multifactor authentication schemes but relies instead on the physical properties of a wireless signal. The APEC protocol provides opportunities for real-time deployment in cell phone network infrastructure, as well as in adverse civil and military applications. Description of the APEC implementation and the corresponding results of the simulation study are presented.

42 - ENGINEERING

Extracting Critical Metals from Authentic Bauxite Residue

Securing domestic sources of critical minerals (CM) is paramount to ensuring a robust and self-sustaining technology infrastructure. Utilizing untapped non-conventional sources, like acid mine drainage, coal ash, bauxite residue/red mud, and more is an emerging approach that addresses this national concern while identifying new value-added pathways originating from waste streams. Red mud is a byproduct of the Bayer process that produces alumina and contains a wealth of CM – 50 µg/g Ga, 2.9 mg/g total rare earth elements plus yttrium, 12 mg/g Mn, 58 mg/g Al, and others. About 170 MM tonnes of red mud are co-produced annually alongside the 142 MM tonnes of alumina generated, highlighting the abundancy of this feedstock. In this work, different strategies were explored for extracting CM from authentic bauxite residue that involve thermal heating, microwave heating, and sonication all with different acids and buffers. CM recovery was then explored one step further by testing the adsorption of the extracted metals onto NETL’s Multi-functional Sorbent Technology (MUST). Microwave treatment of red mud proved the most effective CM extraction, whereas sonication was less desirable due to scale-up concerns. Successful recovery of CM from this leachate with MUST supports further studies toward optimizing the overall process.

bauxite residue

Towards Content Authenticity: Multimodal Fake News Detection and AI-Generated Text Identification

In today’s digital world, the spread of fake news and the rise of AI-generated text have become major threats to content authenticity and public trust. This thesis addresses both challenges through two complementary research directions: detecting fake news using multimodal features, and identifying AI-generated text using semantic and structural reasoning. The first part of the work focuses on fake news detection by introducing a novel model that combines text and image features through a unique rotational attention mechanism. Unlike traditional attention methods, this approach rotates the roles of query, key, and value across modalities to capture deeper interactions. Additionally, the model incorporates external domain information by linking news posts to top-ranked websites from Google search results, which helps assess the credibility of content based on its broader web context. This results in a more reliable and accurate fake news detection system that outperforms existing state-of-the-art methods. The second part presents SGG-ATD, a new framework for detecting AI-generated text. It uses masked language modeling to measure sentence coherence, followed by constructing a graph where keywords—both original and predicted—are connected based on semantic and contextual similarity. A Graph Convolutional Network (GCN) is then used to learn structural relationships within the text for final classification. Experimental results demonstrate that SGG-ATD achieves high F1-scores and consistently outperforms strong baselines. This method contributes to robust AI text detection, supporting accountability and resilience against AI-driven misinformation.

Gupta, Nidhi

COnfirmation using Gamma-ray Non-Imaging Zero-knowledge ANti-mask Time-encoding (COGNIZANT) Final Summary Report

In potential future arms reduction treaties in which the numbers of nuclear warheads may approach small numbers, using delivery systems as a proxy for the warheads themselves may be insufficient. Therefore, a technical means of verifying the presence of a nuclear warhead may become necessary. Verifying that a declared item actually is a warhead is technically challenging within a verification regime: providing assurance to the monitoring party that a presented item is a warhead while protecting sensitive information about that warhead may be required. It is generally believed that strong assurance will require the confirmation of key attributes that may reveal closely-guarded critical design information. This provides high confidence to the monitoring party, but presents a risk of information loss to the host. A verification system must overcome this hurdle. Over the last several decades, systems have been developed that balance host and monitoring partner needs by using sensitive information to confirm treaty accountable items (TAI) as warheads while sequestering that information behind an information barrier (1). These are designed to meet the needs of the host but places the onus on the monitor to authenticate the hardware, firmware, and software. Authentication requires that the monitor confirm that all components of the system have not been modified and work as intended. In 2014, Glaser et al. proposed applying the concept of “zero knowledge protocols” (ZKP) from the field of cryptography to the problem of warhead verification (2). In mathematical cryptography, ZKP is accomplished by challenging one party to solve a problem that is only possible if that party possesses the information being authenticated. After repeated challenges, the party provides confidence that it possesses this information without revealing any details about the information itself. Systems have been in development based on this idea at both Princeton and MIT (2) (3) (4). The final measurement results produced by these systems can be viewed by both the host and the monitoring party without the worry of revealing sensitive information. However, in both of these physical implementations, there remains an information barrier within the system. The need for a digital information barrier to protect a measurement result is eliminated, but it has been replaced with the need to sequester physical components of the system, potentially obfuscating the measurement process itself. Both implementations physically insert information into the system that requires protection to prevent undesired disclosure of sensitive information: in the Princeton method, one must physically load the complement of the expected image of a true warhead into the system, and in the MIT technique, one loads a collection of spectator foils whose thicknesses physically encrypt a measured spectrum. This complicates authentication of the hardware and measurement process. The CONFIDANTE/COGNIZANT concept developed in this project do not load sensitive information into the system at any time, and could therefore open the possibility of allowing the inspector to not only view the final data but also the measurement as it is being performed and all associated equipment.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P

Non-nuclear Component Signatures for Warhead Dismantlement Confirmation

The verification of warhead dismantlement is expected to be an important component in future arms reduction treaties. Historic approaches developed with future arms control treaty verification in mind often involve intrusive measurements, process monitoring, and/or inspector presence to provide confidence that an authentic warhead has been dismantled. This work explores the possibility of reducing the negative impacts of these invasive approaches while also delivering a method that is more likely to provide non-sensitive data that can be shared with not only other nuclear weapons states but also non-nuclear weapons states partners. This work explores a novel approach for verifying dispositioned non-nuclear weapon components, providing confidence post-dismantlement that a treaty accountable item that was dismantled was in fact a treaty-relevant nuclear weapon system as declared. This method provides an alternative to intrusive inspection processes in nuclear weapons production environments, which would require significant changes to the host’s operational behaviors. It achieves this by identifying intrinsic neutron-induced signatures of non-nuclear components to determine their authenticity and estimate the duration they were exposed within a nuclear weapons system using technologies that are already in use for other national security applications. Intrinsic radiation effects studies are already a part of the stockpile aging and surveillance evaluations. However, none of these technologies and approaches have been previously considered for verification applications of non-nuclear component disposition. In this report, we introduce modeling studies that have been used to identify the most promising candidate parts and materials with signatures that are measurable and actionable. These models have been validated with laboratory measurements of signatures induced by the exposure of candidate materials to neutrons over a range of times. Predictive modeling then demonstrates the methodology for estimating exposure times and/or limits. Laboratory measurements of authentic non-nuclear parts from a dismantled warhead demonstrate the feasibility of employing these signature measurements. And finally, a concept of operations (CONOPS) for the potential use of this methodology is presented.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P

TrustDER: Trusted, Private and Scalable Coordination of Distributed Energy Resources

In this project, the Stanford and SLAC Teams have developed a Trusted, Private and Scalable platform for coordinating Coordination of Distributed Energy Resources (TrustDER). This is a layered system that ensures private, trusted and scalable coordination and monitoring of DERs. It accommodates a variety of resources, such as solar generation, gensets and loads, with a particular focus on battery systems-based resources, as they are a transformational technology experiencing fast growth in adoption by large critical facilities. The platform can be used as standalone or added to existing aggregation systems to enable trust, privacy and resilience. TrustDER consists of layers that address each of the shortcomings of the existing state of the art. Each layer in the platform can operate independently but provides information to the layers above it to enable a novel form of overall coordination architecture. The project consists of several tasks, with each task dedicated to the design of each layer. Task 2 Resource Virtualization defined a software abstraction layer for distributed energy resources (DERs). The goal of this abstraction was to simplify the implementation of algorithms utilizing cooperation of DERs resources in a variety of use cases. Task 3 is on Secure ID for Asset Authentication. Identity Management Systems (IDMS) are a foundational infrastructure for interactions between entities (organizations, users, devices, and services). Secure ID is blockchain-based a distributed identity management system allowing (1) identity provisioning, (2) authentication, (3) authorization, and (4) identity data sharing for IoT-enabled assets on the electricity grid. In this project, the SLAC team focused on designing and testing Keymaker, a protocol for authenticating device identity managed by Secure ID. Task 5 Private and Safe Integration is focused on the design and evaluation of a DER cooperation scheme which allows for the aggregation of DERs without impacting network reliability. The approach is designed based on realistic assumptions regarding data availability, communication infrastructure limitations, and privacy. Task 6 Scalable Distributed Privacy for Information explored how virtualized batteries could be managed privately. Specifically, it examined the case in which a principal provides a partitioned battery to multiple clients. Task 7 Use Cases was to ensure that this technology was applied in relevant situations and scenarios. Primarily, this means that virtualization needed to be employed in a manner that either improved flexibility, bolstered security or privacy, or decreased costs.

25 ENERGY STORAGE

Firmware Tampering Detection in Heavy-Duty Vehicles through J1939 CAN Analysis

Modern heavy-duty vehicles rely on complex networks of Electronic Control Units (ECUs) that communicate using the J1939 protocol. While this system makes it easier to update and configure vehicle components, it also opens the door to serious cybersecurity risks if not properly secured. This work investigates the potential for firmware tampering through the J1939 communication protocol, which enables ECU configuration and reprogramming over the Controller Area Network (CAN) bus. By monitoring CAN traffic during legitimate maintenance operations and reverse-engineering OEM diagnostic software, we identified common and proprietary J1939 message identifiers, authentication patterns, and vulnerabilities within Unified Diagnostic Services (UDS). These findings demonstrate that inadequate authentication mechanisms can allow malicious actors to alter ECU firmware or disable safety functions, posing severe operational and safety risks. Our analysis contributes to the development of vehicle intrusion detection systems capable of recognizing abnormal reprogramming activity and future firmware fingerprinting methods to verify software integrity across ECUs. This work highlights the importance of standardizing secure firmware authentication across manufacturers to strengthen cyber resilience in heavy-duty vehicle systems.

33 ADVANCED PROPULSION SYSTEMS

Ammonium-coordinated exchanger (ACE) functionalized silica sorbents for recovering/removing aqueous anionic contaminants

There are limited studies of functionalized silica anion exchange sorbents used for critical/heavy metal recovery/removal relative to polymeric and other inorganic materials. This work features ammonium-coordinated exchanger (ACE) anion exchange particle sorbents prepared by either acid-washing epoxy-crosslinked polyethylenimine (PEI) hydrogen bonded within/to a silica particle sorbent (two-step method) or reacting a di-chlorinated crosslinker, α,α-dichloro-p-xylene (DPX), with PEI within silica (single-step method). Energy dispersive X-ray spectroscopy (EDS) and infrared spectroscopy confirmed the presence of -NH 2 + ···Cl - and -NH 3 + ···Cl - groups, which removed oxyanionic species –arsenate, selenate, chromate, sulfate, phosphate, and nitrate– plus bromide from ideal solutions, authentic acid mine drainage (AMD), and authentic flue gas desulfurization (FGD) wastewater. Affinity of the anions for ACE varied across single- and mixed-element solutions. However, affinity for CrO 4 2- was among the highest in both cases. Total anion uptake by the optimized ACE, PEI-E3-HCl_1.1, reached 1.2 mmol anion/g-sorb. (0.56 mmol CrO 4 2- /g), or ∼2.3 mmol negative charge/g-sorb. This was close to the 0.52 mmol CrO 4 2- /g of a commercial anion exchange resin. Near-consistent removal of 20–80 % of each anion from FGD during an eight-cycle adsorption-desorption (1 M NaCl) test predicted good ACE viability for testing under practical conditions at larger scale.

37 INORGANIC, ORGANIC, PHYSICAL, AND ANALYTICAL CH

Assessing the Impact of Measurement Precision on Metabolite Identification Probability in Multidimensional Mass Spectrometry-Based, Reference-Free Metabolomics

Identification of compounds with minimal ambiguity remains a central challenge in mass spectrometry-based metabolomics. Conventional compound identification relies on comparing analytical signatures (e.g., mass-to-charge ratio, collision cross section, tandem mass spectra) against reference data obtained from measurements of authentic chemical standards. The breadth of annotatable compounds using this approach is necessarily limited by availability of authentic standards, analytical throughput, and resolving power of the separations that underly the measurements. The maturation of computational methods, both theory-driven and artificial intelligence/machine learning-based, for prediction of various molecular properties relevant to multidimensional mass spectrometry measurements has opened the door to a new “reference-free” paradigm of compound annotation. Through augmenting existing reference data for molecular properties with computational predictions, the universe of identifiable chemical species can be expanded significantly beyond its current limits. An unexplored aspect of this novel approach is understanding how to gauge confidence in resulting annotations, especially as the compound search space is expanded. Intuitively, the confidence of a compound annotation is related to the inherent discriminatory power of the molecular properties used for identification, as well as the precision with which the properties are measured or predicted. In this work, we characterize this relationship between measurement precision and identification probability in a systematic and quantitative fashion for a defined region of chemical space that includes organic small molecule metabolites. Importantly, this work establishes a framework for conducting metabolite identification probability analysis that enables others to quantify this relationship for their own compounds and properties of interest.

Metabolite Identification

Model Residuals as Shields: A Two-Level Formulation to Defend Smart Grids From Poisoning Attacks

The advancement of smart grids presents both vast opportunities and heightened cybersecurity risks. Data-driven defense mechanisms, though designed as a shield against these threats, can fall prey to poisoning attacks. We delve into regression settings, underscoring the imperative to fortify defenses against a spectrum of poison ratios, notably those above 0.5—an issue scarcely addressed in prior studies. Recognizing the susceptibilities of smart grids and their manipulable sensors, we exploit the very intent of poisoning attacks, compromising model accuracy, as our defense mechanism. Our proposed two-level optimization framework discerns between poisoned and authentic data based on model residuals, outperforming or matching existing methods in 72% to 77% of precision and 75% to 80% of recalls across various poisoning attacks, poison ratios, and datasets. Once the authentic data are identified, the trained model is adaptable for a variety of applications. Comprehensive evaluations on different smart grid datasets, pitted against myriad poisoning schemes, validate our methodology’s edge over existing methods. Here, we also shed light on the implications of model misspecification originating from temporal auto-correlation, a common feature in Internet of Things and smart grid data.

Adversarial machine learning (ML)

VISTA

SAND2025-14753O VISTA Image Management is a tool that serves as a thin wrapper around S3 storage, enabling teams to create projects, upload images, and add labels to data. It uses standard open-source libraries, employs conventional authentication and authorization methods, and is expected to run behind a reverse proxy that handles authentication. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Garland, Anthony [Sandia National Lab. (SNL-CA), L

The Essence of Cryptol: A Denotational Cryptol Interpreter in Coq for Foundational Assurances for Quantum Resistant Cryptosystems

Systems of the utmost consequence need a means to establish authenticity of software and data. Cryptosystems implement authentication, but can be vulnerable to cryptographic and implementation attacks. With the threat of quantum cryptographic attacks, “post-quantum” cryptosystems (PQCs) must be henceforth used in these systems. However, the new cryptography needs new ways to, rigorously and machine-checkably, prove systems free of vulnerabilities. We propose a retargetable capability to rapidly instantiate proven correct postquantum cryptosystems through novel proof-carrying synthesis and proof-automation technique, extending those proven successful on existing systems. This capability is crucial to meeting the cryptographic requirements for future high-consequence systems. Since specifications for high consequence cryptography are presently captured in a domain specific language known as Cryptol. While this can enable convenient fully automated reasoning about Cryptol specificaitons and implementations via the Software Analysis Workbench (SAW), Cryptol has expressivity gaps, so that cryptosystems with probabilistic programming features like Falcon cannot be fully expressed in the language. Moreover, SAW’s automation fails for programs and specificaitons with inductive and recursive structure, as in the Sphincs+ PQC. Finally, Cryptol and SAW together represent some 200,000 lines of unverified Haskell, so that the any guarantees about high consequence cryptography are presently contingent on a large, unverified, yet trusted computing base. The first step of the larger project of agile, assured crpytography is therefore to provide a formal, mechanized semantics for Cryptol, so that the specifications expressed by cryptographers in Cryptol can be reasoned about and compiled into performant implementations with a foundational, machine checkable certificate of correctness. This report describes our work on this first step, culminating in the design of a certified denotational interpreter, in Coq, for core Cryptol.

97 MATHEMATICS AND COMPUTING