Search NASA⌕ Search

SEARCH · Search NASA

Results for “firewall”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Firewall Traversal for CORBA Applications Using an Implementation of Bidirectional IIOP in MICO

The Object Management Group (OMG) has added specifications to the General Inter-ORB Protocol (GIOP 1.2), specifically the Internet Inter-ORB Protocol (IIOP 1.2), that allow servers and clients on opposing sides of a firewall to reverse roles and still communicate freely. This addition to the GIOP specifications is referred to as Bidirectional GIOP. The implementation of these specifications as applied to communication over TCP/IP connections is referred to as 'Bidirectional Internet Inter-ORB Protocol' or BiDirIIOP. This paper details the implementation and testing of the BiDirIIOP Specification in an open source ORB, MICO, that did not previously support Bidirectional GIOP. It also provides simple contextual information and a description of the OMG GIOP/IIOP messaging protocols.

Griffin, Robert I.↗

Atmospheric Profile Imprint in Firewall Ablation Coefficient

A general formula which expresses the distance along the meteoric fireball trajectory 1 as a function of t is discussed. Differential equations which include the motion and ablation of a single nonfragmenting meteor body are presented. The importance of the atmospheric density profile in the meteor formula is emphasized.

Ceplecha, Z.↗

Modular Firewalls for Storage Areas

Giant honeycomb structures assembled in modular units. Flammable materials stored in cells. Walls insulated with firebrick to prevent spread of fire among cells. Portable, modular barrier withstands heat of combustion for limited time and confines combustion products horizontally to prevent fire from spreading. Barrier absorbs heat energy by ablation and not meant to be reused. Designed to keep fires from spreading among segments of solid rocket propellant in storage, barrier erected between storage units of other flammable or explosive materials; tanks of petroleum or liquid natural gas. Barrier adequate for most industrial purposes.

Fedor, O. H.↗

Safe Grid

The biggest users of GRID technologies came from the science and technology communities. These consist of government, industry and academia (national and international). The NASA GRID is moving into a higher technology readiness level (TRL) today; and as a joint effort among these leaders within government, academia, and industry, the NASA GRID plans to extend availability to enable scientists and engineers across these geographical boundaries collaborate to solve important problems facing the world in the 21 st century. In order to enable NASA programs and missions to use IPG resources for program and mission design, the IPG capabilities needs to be accessible from inside the NASA center networks. However, because different NASA centers maintain different security domains, the GRID penetration across different firewalls is a concern for center security people. This is the reason why some IPG resources are been separated from the NASA center network. Also, because of the center network security and ITAR concerns, the NASA IPG resource owner may not have full control over who can access remotely from outside the NASA center. In order to obtain organizational approval for secured remote access, the IPG infrastructure needs to be adapted to work with the NASA business process. Improvements need to be made before the IPG can be used for NASA program and mission development. The Secured Advanced Federated Environment (SAFE) technology is designed to provide federated security across NASA center and NASA partner's security domains. Instead of one giant center firewall which can be difficult to modify for different GRID applications, the SAFE "micro security domain" provide large number of professionally managed "micro firewalls" that can allow NASA centers to accept remote IPG access without the worry of damaging other center resources. The SAFE policy-driven capability-based federated security mechanism can enable joint organizational and resource owner approved remote access from outside of NASA centers. A SAFE enabled IPG can enable IPG capabilities to be available to NASA mission design teams across different NASA center and partner company firewalls. This paper will first discuss some of the potential security issues for IPG to work across NASA center firewalls. We will then present the SAFE federated security model. Finally we will present the concept of the architecture of a SAFE enabled IPG and how it can benefit NASA mission development.

Chow, Edward T.↗

Methods for designing treatments to reduce interior noise of predominant sources and paths in a single engine light aircraft

The sources and paths by which noise enters the cabin of a small single engine aircraft were determined through a combination of flight and laboratory tests. The primary sources of noise were found to be airborne noise from the propeller and engine casing, airborne noise from the engine exhaust, structureborne noise from the engine/propeller combination and noise associated with air flow over the fuselage. For the propeller, the primary airborne paths were through the firewall, windshield and roof. For the engine, the most important airborne path was through the firewall. Exhaust noise was found to enter the cabin primarily through the panels in the vicinity of the exhaust outlet although exhaust noise entering the cabin through the firewall is a distinct possibility. A number of noise control techniques were tried, including firewall stiffening to reduce engine and propeller airborne noise, to stage isolators and engine mounting spider stiffening to reduce structure-borne noise, and wheel well covers to reduce air flow noise.

Hayden, Richard E.↗

Accessible Telemetry Streams using a Zero Trust Architecture for the Flight Operations Directorate

As a result of information technology based work becoming increasingly distributed, unique challenges have been presented within the realm of defined network perimeters, namely with respect to secure access to resources. Historically, and from a simplistic abstract perspective, the common approach has been to adopt the, so-called, moat model whereby a physical network perimeter (or interconnected perimeters) is defined to encapsulate resources behind a boundary protected by a firewall. Users are provisioned access through a virtual private network (VPN) and may be further constrained to resources through specific firewall allow and disallow rulesets. Virtual Private Networks and firewall rulesets lead to common problems, particularly at scale and, as a result, perimeter-less architectures provided over the public internet are increasingly becoming prevalent, particularly with its more popular implementation, the Zero Trust Architecture. We present a proposed implementation of the Zero Trust Architecture with a particular concrete example utilizing a de-perimeterized network that requires authentication and authorization for each action between nodes and does not operate within an implicit trust boundary. It should be noted that this paper is not an attempt at providing comprehensive resolutions for the specific problem space with respect to perimeter based security and is more directed at providing information with regard to our proposed implementation of a Zero Trust Architecture for the Flight Operations Directorate. We direct the reader to our Introduction and Background section for more details on specific documentation and where it can be located as it relates to de-perimeterization and Zero Trust.

Paul Shoemaker↗

Open Source Service Agent (OSSA) in the intelligence community's Open Source Architecture

The Community Open Source Program Office (COSPO) has developed an architecture for the intelligence community's new Open Source Information System (OSIS). The architecture is a multi-phased program featuring connectivity, interoperability, and functionality. OSIS is based on a distributed architecture concept. The system is designed to function as a virtual entity. OSIS will be a restricted (non-public), user configured network employing Internet communications. Privacy and authentication will be provided through firewall protection. Connection to OSIS can be made through any server on the Internet or through dial-up modems provided the appropriate firewall authentication system is installed on the client.

Fiene, Bruce F.↗

Command and Control of Space Assets Through Internet-Based Technologies Demonstrated

The NASA Glenn Research Center successfully demonstrated a transmission-control-protocol/ Internet-protocol- (TCP/IP) based approach to the command and control of onorbit assets over a secure network. This is a significant accomplishment because future NASA missions will benefit by using Internet-standards-based protocols. Benefits of this Internet-based space command and control system architecture include reduced mission costs and increased mission efficiency. The demonstration proved that this communications architecture is viable for future NASA missions. This demonstration was a significant feat involving multiple NASA organizations and industry. Phillip Paulsen, from Glenn's Project Development and Integration Office, served as the overall project lead, and David Foltz, from Glenn's Satellite Networks and Architectures Branch, provided the hybrid networking support for the required Internet connections. The goal was to build a network that would emulate a connection between a space experiment on the International Space Station and a researcher accessing the experiment from anywhere on the Internet, as shown. The experiment was interfaced to a wireless 802.11 network inside the demonstration area. The wireless link provided connectivity to the Tracking and Data Relay Satellite System (TDRSS) Internet Link Terminal (TILT) satellite uplink terminal located 300 ft away in a parking lot on top of a panel van. TILT provided a crucial link in this demonstration. Leslie Ambrose, NASA Goddard Space Flight Center, provided the TILT/TDRSS support. The TILT unit transmitted the signal to TDRS 6 and was received at the White Sands Second TDRSS Ground Station. This station provided the gateway to the Internet. Coordination also took place at the White Sands station to install a Veridian Firewall and automated security incident measurement (ASIM) system to the Second TDRSS Ground Station Internet gateway. The firewall provides a trusted network for the simulated space experiment. A second Internet connection at the demonstration area was implemented to provide Internet connectivity to a group of workstations to serve as platforms for controlling the simulated space experiment. Installation of this Internet connection was coordinated with an Internet service provider (ISP) and local NASA Johnson Space Center personnel. Not only did this TCP/IP-based architecture prove that a principal investigator on the Internet can securely command and control on-orbit assets, it also demonstrated that valuable virtual testing of planned on-orbit activities can be conducted over the Internet prior to actual deployment in space.

Foltz, David A.↗

[Network Design of the Spaceport Command and Control System]

I helped the Launch Control System (LCS) hardware team sustain the network design of the Spaceport Command and Control System. I wrote the procedure that will be used to satisfy an official hardware test for the hardware carrying data from the Launch Vehicle. I installed hardware and updated design documents in support of the ongoing development of the Spaceport Command and Control System and applied firewall experience I gained during my spring 2017 semester to inspect and create firewall security policies as requested. Finally, I completed several online courses concerning networking fundamentals and Unix operating systems.

Teijeiro, Antonio↗

Kennedy Space Center Timing and Countdown Interface to Kennedy Ground Control Subsystem

Kennedy Ground Control System (KGCS) engineers at the National Aeronautics and Space Administration (NASA) Kennedy Space Center (KSC) are developing a time-tagging process to enable reconstruction of the events during a launch countdown. Such a process can be useful in the case of anomalies or other situations where it is necessary to know the exact time an event occurred. It is thus critical for the timing information to be accurate. KGCS will synchronize all items with Coordinated Universal Time (UTC) obtained from the Timing and Countdown (T&CD) organization. Network Time Protocol (NTP) is the protocol currently in place for synchronizing UTC. However, NTP has a peak error that is too high for today's standards. Precision Time Protocol (PTP) is a newer protocol with a much smaller peak error. The focus of this project has been to implement a PTP solution on the network to increase timing accuracy while introducing and configuring the implementation of a firewall between T&CD and the KGCS network.

Protocol↗

Ceramic-Cord Gas Seal

High-temperature gasket material seals at temperatures above 1,100 degrees C. Concentric exhaust pipes are typical of applications in which ceramic-cord seals might be used. Cord is crushed to form seal between inner and outer pipes when inner pipe is expanded into place. Typical applications include engine exhaust ducts or hot pipes passing through firewalls.

Etzel, C. W.↗

Rule groupings: An approach towards verification of expert systems

Knowledge-based expert systems are playing an increasingly important role in NASA space and aircraft systems. However, many of NASA's software applications are life- or mission-critical and knowledge-based systems do not lend themselves to the traditional verification and validation techniques for highly reliable software. Rule-based systems lack the control abstractions found in procedural languages. Hence, it is difficult to verify or maintain such systems. Our goal is to automatically structure a rule-based system into a set of rule-groups having a well-defined interface to other rule-groups. Once a rule base is decomposed into such 'firewalled' units, studying the interactions between rules would become more tractable. Verification-aid tools can then be developed to test the behavior of each such rule-group. Furthermore, the interactions between rule-groups can be studied in a manner similar to integration testing. Such efforts will go a long way towards increasing our confidence in the expert-system software. Our research efforts address the feasibility of automating the identification of rule groups, in order to decompose the rule base into a number of meaningful units.

Mehrotra, Mala↗

Plasma-Spray Metal Coating On Foam

Molds, forms, and other substrates made of foams coated with metals by plasma spraying. Foam might be ceramic, carbon, metallic, organic, or inorganic. After coat applied by plasma spraying, foam left intact or removed by acid leaching, conventional machining, water-jet cutting, or another suitable technique. Cores or vessels made of various foam materials plasma-coated with metals according to method useful as thermally insulating containers for foods, liquids, or gases, or as mandrels for making composite-material (matrix/fiber) parts, or making thermally insulating firewalls in automobiles.

Cranston, J.↗

High-Temperature Graphite/Phenolic Composite

Graphite-fiber/phenolic-resin composite material retains relatively high strength and modulus of elasticity at temperatures as high as 1,000 degrees F. Costs only 5 to 20 percent as much as refractory materials. Fabrication composite includes curing process in which application of full autoclave pressure delayed until after phenolic resin gels. Curing process allows moisture to escape, so when composite subsequently heated in service, much less expansion of absorbed moisture and much less tendency toward delamination. Developed for nose cone of external fuel tank of Space Shuttle. Other potential aerospace applications for material include leading edges, parts of nozzles, parts of aircraft engines, and heat shields. Terrestrial and aerospace applications include structural firewalls and secondary structures in aircraft, spacecraft, and ships. Modified curing process adapted to composites of phenolic with other fiber reinforcements like glass or quartz. Useful as high-temperature circuit boards and electrical insulators.

Seal, Ellis C.↗

Recent improvements in the NASA technical report server

The NASA Technical Report Server (NTRS), a World Wide Web (WWW) report distribution service, has been modified to allow parallel database queries, significantly decreasing user access time by an average factor of 2.3, access from clients behind firewalls and/or proxies which truncate excessively long Uniform Resource Locators (URL's), access to non-Wide Area Information Server (WAIS) databases, and compatibility with the Z39-50.3 protocol.

Maa, Ming-Hokng↗

General Aviation Interior Noise: Source/Path Identification - Part 1

There were two primary objectives of the research effort reported herein. The first objective was to identify and evaluate noise source/path identification technology applicable to single engine propeller driven aircraft that can be used to identify interior noise sources originating from structure-borne engine/propeller vibration, airborne propeller transmission, airborne engine exhaust noise, and engine case radiation. The approach taken to identify the contributions of each of these possible sources was first to conduct a Principal Component Analysis (PCA) of an in-flight noise and vibration database acquired on a Cessna Model 182E aircraft. The second objective was to develop and evaluate advanced technology for noise source ranking of interior panel groups such as the aircraft windshield, instrument panel, firewall, and door/window panels within the cabin of a single engine propeller driven aircraft. The technology employed was that of Acoustic Holography (AH). AH was applied to the test aircraft by acquiring a series of in-flight microphone array measurements within the aircraft cabin and correlating the measurements via PCA. The source contributions of the various panel groups leading to the array measurements were then synthesized by solving the inverse problem using the boundary element model.

Unruh, James F.↗

Security for Multimedia Space Data Distribution over the Internet

Distribution of interactive multimedia to remote investigators will be required for high quality science on the International Space Station (ISS). The Internet with the World Wide Web (WWW) and the JAVA environment are a good match for distribution of data, video and voice to remote science centers. Utilizing the "open" Internet in a secure manner is the major hurdle in making use of this cost effective, off-the-shelf, universal resource. This paper examines the major security threats to an Internet distribution system for payload data and the mitigation of these threats. A proposed security environment for the Space Station Biological Research Facility (SSBRP) is presented with a short description of the tools that have been implemented or planned. Formulating and implementing a security policy, firewalls, host hardware and software security are also discussed in this paper. Security is a vast topic and this paper can only give an overview of important issues. This paper postulates that a structured approach is required and stresses that security must be built into a network from the start. Ignoring security issues or putting them off until late in the development cycle can be disastrous.

Stone, Thom↗