Search NASA⌕ Search

SEARCH · Search NASA

Results for “secure remote access”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Secure Remote Access Issues in a Control Center Environment

The ISS finally reached an operational state and exists for local and remote users. Onboard payload systems are managed by the Huntsville Operations Support Center (HOSC). Users access HOSC systems by internet protocols in support of daily operations, preflight simulation, and test. In support of this diverse user community, a modem security architecture has been implemented. The architecture has evolved over time from an isolated but open system to a system which supports local and remote access to the ISS over broad geographic regions. This has been accomplished through the use of an evolved security strategy, PKI, and custom design. Through this paper, descriptions of the migration process and the lessons learned are presented. This will include product decision criteria, rationale, and the use of commodity products in the end architecture. This paper will also stress the need for interoperability of various products and the effects of seemingly insignificant details.

Pitts, Lee↗

Safe Grid

The biggest users of GRID technologies came from the science and technology communities. These consist of government, industry and academia (national and international). The NASA GRID is moving into a higher technology readiness level (TRL) today; and as a joint effort among these leaders within government, academia, and industry, the NASA GRID plans to extend availability to enable scientists and engineers across these geographical boundaries collaborate to solve important problems facing the world in the 21 st century. In order to enable NASA programs and missions to use IPG resources for program and mission design, the IPG capabilities needs to be accessible from inside the NASA center networks. However, because different NASA centers maintain different security domains, the GRID penetration across different firewalls is a concern for center security people. This is the reason why some IPG resources are been separated from the NASA center network. Also, because of the center network security and ITAR concerns, the NASA IPG resource owner may not have full control over who can access remotely from outside the NASA center. In order to obtain organizational approval for secured remote access, the IPG infrastructure needs to be adapted to work with the NASA business process. Improvements need to be made before the IPG can be used for NASA program and mission development. The Secured Advanced Federated Environment (SAFE) technology is designed to provide federated security across NASA center and NASA partner's security domains. Instead of one giant center firewall which can be difficult to modify for different GRID applications, the SAFE "micro security domain" provide large number of professionally managed "micro firewalls" that can allow NASA centers to accept remote IPG access without the worry of damaging other center resources. The SAFE policy-driven capability-based federated security mechanism can enable joint organizational and resource owner approved remote access from outside of NASA centers. A SAFE enabled IPG can enable IPG capabilities to be available to NASA mission design teams across different NASA center and partner company firewalls. This paper will first discuss some of the potential security issues for IPG to work across NASA center firewalls. We will then present the SAFE federated security model. Finally we will present the concept of the architecture of a SAFE enabled IPG and how it can benefit NASA mission development.

Chow, Edward T.↗

Controlling Infrastructure Costs: Right-Sizing the Mission Control Facility

Johnson Space Center's Mission Control Center is a space vehicle, space program agnostic facility. The current operational design is essentially identical to the original facility architecture that was developed and deployed in the mid-90's. In an effort to streamline the support costs of the mission critical facility, the Mission Operations Division (MOD) of Johnson Space Center (JSC) has sponsored an exploratory project to evaluate and inject current state-of-the-practice Information Technology (IT) tools, processes and technology into legacy operations. The general push in the IT industry has been trending towards a data-centric computer infrastructure for the past several years. Organizations facing challenges with facility operations costs are turning to creative solutions combining hardware consolidation, virtualization and remote access to meet and exceed performance, security, and availability requirements. The Operations Technology Facility (OTF) organization at the Johnson Space Center has been chartered to build and evaluate a parallel Mission Control infrastructure, replacing the existing, thick-client distributed computing model and network architecture with a data center model utilizing virtualization to provide the MCC Infrastructure as a Service. The OTF will design a replacement architecture for the Mission Control Facility, leveraging hardware consolidation through the use of blade servers, increasing utilization rates for compute platforms through virtualization while expanding connectivity options through the deployment of secure remote access. The architecture demonstrates the maturity of the technologies generally available in industry today and the ability to successfully abstract the tightly coupled relationship between thick-client software and legacy hardware into a hardware agnostic "Infrastructure as a Service" capability that can scale to meet future requirements of new space programs and spacecraft. This paper discusses the benefits and difficulties that a migration to cloud-based computing philosophies has uncovered when compared to the legacy Mission Control Center architecture. The team consists of system and software engineers with extensive experience with the MCC infrastructure and software currently used to support the International Space Station (ISS) and Space Shuttle program (SSP).

Martin, Keith↗

NASA's Implementation of Cloud Services for Human Space Flight

Cloud is a tried-and-true technology used throughout United States government agencies, including the National Aeronautics and Space Administration (NASA). With reliable results and infrequent downtimes, cloud allows for secure remote access, customizability, and streamlined monitoring options, creating an environment for better data integrity and availability. As NASA increasingly migrates functions to the cloud, the Space Communications and Navigation Program (SCaN) program has been investigating how this capability can be leveraged to provide communication services to its users and customers. Currently, missions such as NASA-ISRO Synthetic Aperture Radar (NISAR), Plankton, Aerosol, Cloud, ocean Ecosystem (PACE), and Roman Space Telescope (RST) are planned to incorporate cloud into their data delivery architecture. However, SCaN is looking to expand further. This conversion to using cloud services allows for greater availability of mission data for both robotic and human space flight (HSF)missions. The SCaN program and the Near Space Network (NSN) are working to consolidate resources and create a cloud environment suitable for the entirety of the SCaN program network architecture. SCaN is in the process of finalizing its cloud architecture and soon will be implementing cloud services. The new services used will adhere to federal regulations including Federal Risk and Authorization Management Program (FedRAMP), which is built upon National Institute of Standards and Technology (NIST)documentation. While keeping in mind these security requirements, an auxiliary objective of the cloud integration is to ensure the most cost-efficient solution; providing a scalable, robust and resilient system. Using cloud services, NASA will gain access to better centralized monitoring and management features, along with customizable services on a pay-per-use plan. With the ever-growing NASA mission data volume needs, maintaining ample storage space is another major constraint. Processing and storing such large amounts of data, on the order of terabytes a day, requires dynamic processing capability which is inherently a strength of cloud computing. By routing this data from ground stations through the cloud, there will be greater ease of access for both SCaN and the user community. Artificial intelligence and other built-in cloud functions can also enhance efficiency, improving data processing time. Thereby also allowing for better data availability. As we look to the future of cloud services, NASA will continue to leverage capabilities that will benefit NASA’s ability to provide cost-effective communication services. This paper further outlines the evolution of cloud use by SCaN in the context of Human Space Flight.

cloud storage↗

Technology

Session WA3 includes short reports concerning: (1) Physiolab A Cardio Vascular Laboratory; (2) MEDEX: A Flexible Modular Physiological Laboratory; (3) A Sensate Liner for Personnel Monitoring Applications; (4) Secure Remote Access to Physiological Data; (5) DARA Vestibular Equipment Onboard MIR; (6) The Kinelite Project: A New powerful Motion Analysis System for Spacelab Mission; (7) The Technical Evolution of the French Neurosciences Multipurpose Instruments Onboard the MIR Station; (8) Extended Ground-Based Research in Preparation for Life Sciences Experiments; and (9) MEDES Clinical Research Facility as a Tool to Prepare ISSA Space Flights.

Source record↗

The D3 Middleware Architecture

DARWIN is a NASA developed, Internet-based system for enabling aerospace researchers to securely and remotely access and collaborate on the analysis of aerospace vehicle design data, primarily the results of wind-tunnel testing and numeric (e.g., computational fluid-dynamics) model executions. DARWIN captures, stores and indexes data; manages derived knowledge (such as visualizations across multiple datasets); and provides an environment for designers to collaborate in the analysis of test results. DARWIN is an interesting application because it supports high-volumes of data. integrates multiple modalities of data display (e.g., images and data visualizations), and provides non-trivial access control mechanisms. DARWIN enables collaboration by allowing not only sharing visualizations of data, but also commentary about and views of data. Here we provide an overview of the architecture of D3, the third generation of DARWIN. Earlier versions of DARWIN were characterized by browser-based interfaces and a hodge-podge of server technologies: CGI scripts, applets, PERL, and so forth. But browsers proved difficult to control, and a proliferation of computational mechanisms proved inefficient and difficult to maintain. D3 substitutes a pure-Java approach for that medley: A Java client communicates (though RMI over HTTPS) with a Java-based application server. Code on the server accesses information from JDBC databases, distributed LDAP security services, and a collaborative information system. D3 is a three tier-architecture, but unlike 'E-commerce' applications, the data usage pattern suggests different strategies than traditional Enterprise Java Beans - we need to move volumes of related data together, considerable processing happens on the client, and the 'business logic' on the server-side is primarily data integration and collaboration. With D3, we are extending DARWIN to handle other data domains and to be a distributed system, where a single login allows a user transparent access to test results from multiple servers and authority domains.

Walton, Joan↗

D3: A Collaborative Infrastructure for Aerospace Design

DARWIN is a NASA developed, Internet-based system for enabling aerospace researchers to securely and remotely access and collaborate on the analysis of aerospace vehicle design data, primarily the results of wind-tunnel testing and numeric (e.g., computational fluid dynamics) model executions. DARWIN captures, stores and indexes data, manages derived knowledge (such as visualizations across multiple data sets) and provides an environment for designers to collaborate in the analysis of the results of testing. DARWIN is an interesting application because it supports high volumes of data, integrates multiple modalities of data display (e.g. images and data visualizations), and provides non-trivial access control mechanisms. DARWIN enables collaboration by allowing not only sharing visualizations of data, but also commentary about and view of data.

Walton, Joan↗

Accessing Wind Tunnels From NASA's Information Power Grid

The NASA Ames wind tunnel customers are one of the first users of the Information Power Grid (IPG) storage system at the NASA Advanced Supercomputing Division. We wanted to be able to store their data on the IPG so that it could be accessed remotely in a secure but timely fashion. In addition, incorporation into the IPG allows future use of grid computational resources, e.g., for post-processing of data, or to do side-by-side CFD validation. In this paper, we describe the integration of grid data access mechanisms with the existing DARWIN web-based system that is used to access wind tunnel test data. We also show that the combined system has reasonable performance: wind tunnel data may be retrieved at 50Mbits/s over a 100 base T network connected to the IPG storage server.

Becker, Jeff↗

Achievable Performance and Effective Interrogator Design for SAW RFID Sensor Tags

For many NASA missions, remote sensing is a critical application that supports activities such as environmental monitoring, planetary science, structural shape and health monitoring, non-destructive evaluation, etc. The utility of the remote sensing devices themselves is greatly increased if they are passive V that is, they do not require any on-board power supply such as batteries V and if they can be identified uniquely during the sensor interrogation process. Additional passive sensor characteristics that enable greater utilization in space applications are small size and weight, long read ranges with low interrogator power, ruggedness, and operability in extreme environments (vacuum, extreme high/low temperature, high radiation, etc.) In this paper, we consider one very promising passive sensor technology, called surface acoustic wave (SAW) radio-frequency identification (RFID), that satisfies all of these criteria. In general, RFID is a method of identifying items using radio waves to interrogate tags encoded with a unique identifier that are affixed to the items of interest. In the case of passive tags, only the interrogator, which transmits power to the tags in the form of radio-frequency electromagnetic radiation, requires access to a power supply. Passive RFID technologies are used today in many applications, including asset tracking and management, security and access control, and remote sensing. To date, most of the development and application in RFID technology has focused on either asset/inventory tracking and control or security and access control because these are the largest commercial application areas. Recently however, there has been growing interest in using passive RFID technology for remote sensing applications, and SAW devices are at the forefront of RFID sensing technology development. Although SAW RFID tags have great potential for use in numerous space-based remote sensing applications, the limited collision resolution capability of current generation tags limits the performance in a cluttered sensing environment. That is, as more SAW-based sensors are added to the environment, numerous tag responses are superimposed at the receiver and decoding all or even a subset of the telemetry becomes increasingly difficult. Background clutter generated by reflectors other than the sensors themselves is also a problem, as is multipath interference and signal distortion, but the limiting factor in many remote sensing applications can be expected to be tag mutual interference. This problem may be greatly mitigated by proper design of the SAW tag waveform, but that remains an open research problem, and in the meantime, several other related questions remain to be answered including: (1) What are the fundamental relationships between tag parameters such as bit-rate, time-bandwidth-product, SNR, and achievable collision resolution? (2) What are the differences in optimal or near-optimal interrogator designs between noise-limited environments and interference-limited environments? (3) What are the performance characteristics of different interrogator designs in term of parameters such as transmitter power level, range, and number of interfering tags? In this paper, we will present the results of a research effort aimed at providing at least partial answers to all of these questions.

Barton Richard J.↗

FERMI/GLAST Integrated Trending and Plotting System Release 5.0

An Integrated Trending and Plotting System (ITPS) is a trending, analysis, and plotting system used by space missions to determine performance and status of spacecraft and its instruments. ITPS supports several NASA mission operational control centers providing engineers, ground controllers, and scientists with access to the entire spacecraft telemetry data archive for the life of the mission, and includes a secure Web component for remote access. FERMI/GLAST ITPS Release 5.0 features include the option to display dates (yyyy/ddd) instead of orbit numbers along orbital Long-Term Trend (LTT) plot axis, the ability to save statistics from daily production plots as image files, and removal of redundant edit/create Input Definition File (IDF) screens. Other features are a fix to address invalid packet lengths, a change in naming convention of image files in order to use in script, the ability to save all ITPS plot images (from Windows or the Web) as GIF or PNG format, the ability to specify ymin and ymax on plots where previously only the desired range could be specified, Web interface capability to plot IDFs that contain out-oforder page and plot numbers, and a fix to change all default file names to show yyyydddhhmmss time stamps instead of hhmmssdddyyyy. A Web interface capability sorts files based on modification date (with newest one at top), and the statistics block can be displayed via a Web interface. Via the Web, users can graphically view the volume of telemetry data from each day contained in the ITPS archive in the Web digest. The ITPS could be also used in nonspace fields that need to plot data or trend data, including financial and banking systems, aviation and transportation systems, healthcare and educational systems, sales and marketing, and housing and construction.

Ritter, Sheila↗

Secure Payload Access to the International Space Station

The ISS finally reached an operational state and exists for local and remote users. Onboard payload systems are managed by the Huntsville Operations Support Center (HOSC). Users access HOSC systems by internet protocols in support of daily operations, preflight simulation, and test. In support of this diverse user community, a modem security architecture has been implemented. The architecture has evolved over time from an isolated but open system to a system which supports local and remote access to the ISS over broad geographic regions. This has been accomplished through the use of an evolved security strategy, PKI, and custom design. Through this paper, descriptions of the migration process and the lessons learned are presented. This will include product decision criteria, rationale, and the use of commodity products in the end architecture. This paper will also stress the need for interoperability of various products and the effects of seemingly insignificant details.

Pitts, R. Lee↗

Summary of ADTT Website Functionality and Features

This report summarizes development of the ADTT web-based design environment by the ELORET team in 2000. The Advanced Design Technology Testbed had been in development for several years, with demonstration applications restricted to aerodynamic analyses of subsonic aircraft. The key changes achieved this year were improvements in Web-based accessibility, evaluation of collaborative visualization, remote invocation of geometry updates and performance analysis, and application to aerospace system analysis. Significant effort was also devoted to post-processing of data, chiefly through comparison of similar data for alternative vehicle concepts. Such comparison is an essential requirement for designers to make informed choices between alternatives. The next section of this report provides more discussion of the goals for ADTT development. Section 3 provides screen shots from a sample session in the ADTT environment, including Login and navigation to the project of interest, data inspection, analysis execution and output evaluation. The following section provides discussion of implementation details and recommendations for future development of the software and information technologies that provide the key functionality of the ADTT system. Section 5 discusses the integration architecture for the system, which links machines running different operating systems and provides unified access to data stored in distributed locations. Security is a significant issue for this system, especially for remote access to NAS machines, so Section 6 discusses several architectural considerations with respect to security. Additional details of some aspects of ADTT development are included in Appendices.

Hawke, Veronica↗

A Simple XML Producer-Consumer Protocol

There are many different projects from government, academia, and industry that provide services for delivering events in distributed environments. The problem with these event services is that they are not general enough to support all uses and they speak different protocols so that they cannot interoperate. We require such interoperability when we, for example, wish to analyze the performance of an application in a distributed environment. Such an analysis might require performance information from the application, computer systems, networks, and scientific instruments. In this work we propose and evaluate a standard XML-based protocol for the transmission of events in distributed systems. One recent trend in government and academic research is the development and deployment of computational grids. Computational grids are large-scale distributed systems that typically consist of high-performance compute, storage, and networking resources. Examples of such computational grids are the DOE Science Grid, the NASA Information Power Grid (IPG), and the NSF Partnerships for Advanced Computing Infrastructure (PACIs). The major effort to deploy these grids is in the area of developing the software services to allow users to execute applications on these large and diverse sets of resources. These services include security, execution of remote applications, managing remote data, access to information about resources and services, and so on. There are several toolkits for providing these services such as Globus, Legion, and Condor. As part of these efforts to develop computational grids, the Global Grid Forum is working to standardize the protocols and APIs used by various grid services. This standardization will allow interoperability between the client and server software of the toolkits that are providing the grid services. The goal of the Performance Working Group of the Grid Forum is to standardize protocols and representations related to the storage and distribution of performance data. These standard protocols and representations must support tasks such as profiling parallel applications, monitoring the status of computers and networks, and monitoring the performance of services provided by a computational grid. This paper describes a proposed protocol and data representation for the exchange of events in a distributed system. The protocol exchanges messages formatted in XML and it can be layered atop any low-level communication protocol such as TCP or UDP Further, we describe Java and C++ implementations of this protocol and discuss their performance. The next section will provide some further background information. Section 3 describes the main communication patterns of our protocol. Section 4 describes how we represent events and related information using XML. Section 5 describes our protocol and Section 6 discusses the performance of two implementations of the protocol. Finally, an appendix provides the XML Schema definition of our protocol and event information.

Smith, Warren↗

Spacecraft Power Source Installation at Launch Complex

For certain space missions, an assembly must be integrated onto the spacecraft as late as possible in the launch vehicle processing flow. 12This late integration can be driven for a variety of reasons including thermal or hazardous materials constraints. This paper discusses the process of integrating an assembly onto a spacecraft as late as one week prior to the opening of the launch window. Consideration is given to achieving sufficient access for hardware integration, methods of remotely securing hardware to the spacecraft, maintaining spacecraft cleanliness throughout the integration process, and electrically integrating the component to the spacecraft. Specific examples are taken from the remote mechanical, electrical, and fluid cooling system integration of the power source onto the Mars Science Laboratory (MSL) Rover at the Atlas V Vertical Integration Facility (VIF) at Cape Canaveral Air Force Station, Florida.

Lytal, Paul↗

Security Data Warehouse Application

The Security Data Warehouse (SDW) is used to aggregate and correlate all JSC IT security data. This includes IT asset inventory such as operating systems and patch levels, users, user logins, remote access dial-in and VPN, and vulnerability tracking and reporting. The correlation of this data allows for an integrated understanding of current security issues and systems by providing this data in a format that associates it to an individual host. The cornerstone of the SDW is its unique host-mapping algorithm that has undergone extensive field tests, and provides a high degree of accuracy. The algorithm comprises two parts. The first part employs fuzzy logic to derive a best-guess host assignment using incomplete sensor data. The second part is logic to identify and correct errors in the database, based on subsequent, more complete data. Host records are automatically split or merged, as appropriate. The process had to be refined and thoroughly tested before the SDW deployment was feasible. Complexity was increased by adding the dimension of time. The SDW correlates all data with its relationship to time. This lends support to forensic investigations, audits, and overall situational awareness. Another important feature of the SDW architecture is that all of the underlying complexities of the data model and host-mapping algorithm are encapsulated in an easy-to-use and understandable Perl language Application Programming Interface (API). This allows the SDW to be quickly augmented with additional sensors using minimal coding and testing. It also supports rapid generation of ad hoc reports and integration with other information systems.

Vernon, Lynn R.↗

Remote Concurrent Engineering: A-Team Studies in the Virtual World

NASA Jet Propulsion Laboratory’s (JPL’s)Architecture Team (A-Team) has nearly a decade of experiencein maturing early formulation mission and technology conceptsby combining innovative collaborative engineering methodswith cutting-edge subject matter expertise and advancedanalysis tools in an in-person environment. When COVID-19forced JPL’s workforce to work remotely in March 2020, ATeamhad to quickly pivot from an in-person collaborativeenvironment to a remote working environment.Through introspection, careful planning, and considerablepractice, A-Team was able to develop new operating proceduresto effectively continue early formulation studies in a virtualenvironment. A-Team has held over 57 remote studies in the 10months since the start of mandatory telework at JPL in March2020. In the remote setting, A-Team conducts studies in half-daysessions with clients and subject matter experts (SMEs) viavideoconferencing, shared computer screens, and digitalcollaborative tools.The key lesson is that increased staffing and planning is neededto prepare and successfully run remote A-Team studies. RemoteA-Team studies require careful selection of the appropriatetools for security, accessibility, and usability within theNASA/JPL environment. Knowledge capture methods andtemplates need to be thought out and agreed upon in advance asthere is less room for improvising in a remote format. Variouscommunication channels have to be monitored to allow for teamcoordination while maintaining fruitful participant engagementduring a session. In addition, technical backup for all roleswithin the A-Team have to be identified to allow the study tocontinue even if a team member’s connectivity is temporarilyinterrupted. Finally, careful thought has to be put into methodsand processes to create a collaborative environment in a virtualspace such that a group of experts who are only connected viathe internet can experience the creative spark and flow of a greatcollaborative and innovative study.

Zusack, Steven↗

A Central Asia Hydrologic Monitoring Dataset for Food and Water Security Applications in Afghanistan

From the Hindu Kush mountains to the Registan Desert, Afghanistan is a diverse landscape where droughts, floods, conflict, and economic market accessibility pose challenges for agricultural livelihoods and food security. The ability to remotely monitor environmental conditions is critical to support decision making for humanitarian assistance. The Famine Early Warning Systems Network (FEWS NET) Land Data Assimilation System (FLDAS) global and Central Asia data streams provide information on hydrologic states for routine integrated food security analysis. While developed for a specific project, these data are publicly available and useful for other applications that require hydrologic estimates of the water and energy balance. These two data streams are unique because of their suitability for routine monitoring, as well as for being a historical record for computing relative indicators of water availability. The global stream is available at ∼ 1-month latency, and monthly average outputs are on a 10 km grid from 1982–present. The second data stream, Central Asia (21–56°N, 30–100°E), at ∼ 1 d latency, provides daily average outputs on a 1 km grid from 2000–present. This paper describes the configuration of the two FLDAS data streams, background on the software modeling framework, selected meteorological inputs and parameters, and results from previous evaluation studies. We also provide additional analysis of precipitation and snow cover over Afghanistan. We conclude with an example of how these data are used in integrated food security analysis. For use in new and innovative studies that will improve understanding of this region, these data are hosted by U.S. Geological Survey data portals and the National Aeronautics and Space Administration (NASA). The Central Asia data described in this paper can be accessed via the NASA repository at https://doi.org/10.5067/VQ4CD3Y9YC0R (Jacob and Slinski, 2021), and the global data described in this paper can be accessed via the NASA repository at https://doi.org/10.5067/5NHC22T9375G (McNally, 2018).

Amy McNally↗

IsoWAN: A NASA Science and Engineering Information and Services Framework

We believe that the next evolutionary step in supporting wide-area application and services delivery to customers is a network framework that provides for collocation of applications and services at distinct sites in the network, an interconnection between these sites that is performance optimized for these applications, and value-added services for applications. We use the term IsoWAN to describe an advanced, isolated network interconnect services framework that will enable applications to be more secure, and able to access and be in use in both local and remote environments. The main functions of an IsoWAN are virtual localization of application services, an application service interface, coordinated delivery of applications and associated data to the customer, and supporting collaborative application development for customers. An initial pilot network between three NASA Centers: Ames Research Center, the Jet Propulsion Laboratory, and Marshall Space Flight Center, has been built and its properties will be discussed.

Korsmeyer, David J.↗