Search NASA⌕ Search

SEARCH · Search NASA

Results for “security and privacy”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Zero-Trust Architecture for Autonomous Edge Computing

We are at the apex of an aviation revolution where autonomy will play a central role in enabling complex, multi-agent systems to communicate, interact, and collaborate on a myriad of applications spanning autonomous swarms to wild-fire management. Autonomy is not an absolute but rather a spectrum ranging from a system requiring significant human intervention to one requiring little to none [1]. For example, the extreme, in the case of an autonomous aircraft, is one that operates independently in the airspace interacting with all other elements (air traffic controllers, other pilots) as if it were a human pilot. Critical to this vision is an architecture that enables autonomous agents to interact with minimal latency. Edge computing is an emerging architecture where compute and storage is pushed to the ‘edge’ of the network in order to minimize the round-trip time from agent to resource thereby mitigating the latency associated with cloud-only based approaches. Additionally, services can generate massive amounts of data (e.g., video feeds), which may require analysis in near real-time. Moving this data to the cloud for further processing may not be feasible due to latency, bandwidth, and cost. Privacy, security, and reliability can also be improved by edge computing architectures. However, this geo-distributed and dynamic* architecture complicates the establishment of unambiguous network security boundaries and can lead to vulnerabilities including man in the middle attacks, replay attacks, physical security breaches of edge nodes, signal interception, etc. This motivates the need for zero-trust architectures [2–4] which de-emphasize the notion of static network perimeters and, as the name implies, do not instill any innate trust in any particular agent. It is required that all agents must be authorized and approved in every transaction. In this paper, we present a zero-trust architecture suitable for edge-computing applications that demand significant low-latency, security, privacy, and reliability.

zero trust↗

Security and Privacy Issues in New 5G and 6G Capabilities

Slides for opening INL hosted panel on Security and Privacy Issues in New 5G and 6G Capabilities in the Security and Privacy of Next-Generation Networks (FutureG) Workshop co-located with NDSS Symposium 2025, San Diego, CA.

5G Security↗

Secure and Privacy Aware Data Sharing Approach for Smart Electric Vehicles

The integration of smart electric vehicles (SEVs) into smart cities marks a significant step toward creating efficient, sustainable, and connected urban spaces. However, secure and private data sharing is a major challenge as SEVs connect with smart city systems. The interaction between SEVs and consumer electronic devices (CEDs) raises serious concerns about data security and privacy. Here, to address these challenges, this article presents how blockchain technology and federated learning (FL) can address these issues. The proposed approach provides a secure and privacy-aware framework for data exchange between SEVs and CEDs in smart cities. The experiment results demonstrate the effectiveness of the proposed framework for secure data sharing and maintaining system reliability in smart city environments. It also enables trust and promotes the widespread adoption of interconnected urban technologies.

Das, Debashis [Meharry Medical College, Nashville,↗

Privacy-preserving Information Security for the Energy Grid of Things

Smart grid infrastructure relies on information exchange between multiple actors in order to ensure system reliability. These actors include but are not limited to smart loads, grid control, and energy management technologies. Further, as information exchange between these actors is susceptible to cyber-attacks, security and privacy issues are indispensable to ensure a reliable and stable grid. This position paper proposes a privacy-preserving, trust-augmented secure scheme for a smart grid implementation.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Blockchain-Enabled Secure Device-to-Device Communication in Software-Defined Networking

The Internet of Things (IoT) continues to increase the demand for seamless communication among IoT devices. The rapid growth of IoT devices has led to an exponential increase in device-to-device (D2D) communication within the Software-Defined Networking (SDN), though it enables a flexible archi-tecture for managing network resources. However, traditional security models face challenges (e.g., Security, privacy, and trust) in addressing the dynamic and decentralized nature of these communications. Despite of these challenges, this paper proposes a novel approach that leverages blockchain technology to enhance the security, privacy, and trustworthiness of D2D communication within an SDN environment. The proposed approach integrates blockchain nodes in sDN components to establish a decentralized ledger for transparent and verifiable records. Smart contracts enforce authentication rules to ensure that only authenticated devices can access the network and engage in transactions securely. It also automates the security policies to ensure temper resistance execution using the cryptographic mechanism for data integrity and authentic communication. The Implementation of the proposed algorithms validates the resilience of the proposed approach against cyberattacks. Overall, the proposed approach enables efficient and secure D2D communication for resilient SDN infrastructure in IoT ecosystems.

Das, Debashis↗

Isolating Insecurely: A Call to Arms for the Security and Privacy Community During the Time of COVID-19

The privacy question is one that has only begun to be addressed. While on one hand, many of the staunchest privacy advocates have argued for relaxation of privacy controls in order to develop better tests, “back to work” protocols, and vaccines and other treatments, the same advocates point out that any loss of privacy for the public good should be temporary, transparent, necessary, proportionate, and follow a due process. What should solutions look like for data gathering, sharing, use, and disposal; or for protocols requiring strong individual identity verification and validation?

99 GENERAL AND MISCELLANEOUS↗

Federated Learning and Differential Privacy: What might AI-Enhanced co-design of microelectronics learn?

Data is a valuable commodity, and it is often dispersed over multiple entities. Sharing data or models created from the data is not simple due to concerns regarding security, privacy, ownership, and model inversion. This limitation in sharing can hinder model training and development. Federated learning can enable data or model sharing across multiple entities that control local data without having to share or exchange the data themselves. Differential privacy is a conceptual framework that brings strong mathematical guarantee for privacy protection and helps provide a quantifiable privacy guarantee to any data or models shared. The concepts of federated learning and differential privacy are introduced along with possible connections. Lastly, some open discussion topics on how federated learning and differential privacy can tied to AI-Enhanced co-design of microelectronics are highlighted.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Giving the Public a Perspective into Unmanned Aircraft Systems' Operations

NASA is currently engaged in research to safely enable large-scale commercial applications of small Unmanned Aerial Systems (UAS) in low altitude airspace. This research effort, referred to as UAS Traffic Management (UTM), encompasses the concepts and technologies needed to accommodate the projected demand of UAS operating in the national airspace. One aspect related to the successful implementation of UTM in the future is public acceptance. Transparency will heavily influence this acceptance, and a public portal will provide much of that transparency through ease of access to information about the operations - mainly who, why, and where such operations are taking place. Related concerns to the public are individual privacy, security, and accountability of the operators. Providing the aforementioned information about operations can mitigate these concerns, but a balance will have to be achieved between the need for transparency from the public and the privacy of the operators. The proper balance and the needs of the various UTM stakeholders with regard to information access will be explored through the development and testing of a public portal as part of NASA's Technical Capability 3 (TCL 3) demonstration. Additionally, various approaches to the display of information and user interfaces will be surveyed through the development of a public portal by multiple UTM industry partners across different test sites.

UAS↗

Development of an Energy Services Interface for the EGoT

The Energy Services Interface (ESI) is a set of rules that ensure private, secure, and trustworthy information exchange between Grid Service Providers (GSPs) and utility customers. Large-scale adoption of Distributed Energy Resources (DERs) will be necessary for GSPs to dispatch effective grid services, and to stimulate technological innovations in DER and DERMS (DER Management Systems) technologies, as well as novel grid service programs. The ESI promotes these objectives by advancing a set of rules and interoperability requirements that define bi-directional, service-oriented, logical interfaces between GSPs and customers’ DERs, with expectations for privacy, security, and trust. The ESI rules and interoperability requirements establish boundaries between customers and GSPs that delineate the functions and responsibilities that must be implemented by the developers of Energy Grid of Things (EGoT) ecosystem products. These rules impose constraints on the implementation of a DERMS. The ESI interoperability requirements are based on the Interoperability Maturity Model (IMM), developed by the Grid Modernization Laboratory Consortium. By emphasizing private, secure, and trustworthy information exchange, and by mandating a service-oriented and interoperable architecture, the ESI promotes the development of an EGoT ecosystem that motivates customer participation and technological innovation. Interoperability will encourage innovation by reducing barriers to entry and increasing confidence of stakeholders. Customers will be willing to participate in DER service programs that establish trust and emphasize customer choice. Large-scale customer participation ensures GSPs have ample DER resources to provide grid services that have significant impact on grid reliability and reduce electricity cost for consumers. This in turn signals economic opportunities that encourage innovation, resulting in the development of a robust EGoT ecosystem.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cloud Computing for Mission Design and Operations

The space mission design and operations community already recognizes the value of cloud computing and virtualization. However, natural and valid concerns, like security, privacy, up-time, and vendor lock-in, have prevented a more widespread and expedited adoption into official workflows. In the interest of alleviating these concerns, we propose a series of guidelines for internally deploying a resource-oriented hub of data and algorithms. These guidelines provide a roadmap for implementing an architecture inspired in the cloud computing model: associative, elastic, semantical, interconnected, and adaptive. The architecture can be summarized as exposing data and algorithms as resource-oriented Web services, coordinated via messaging, and running on virtual machines; it is simple, and based on widely adopted standards, protocols, and tools. The architecture may help reduce common sources of complexity intrinsic to data-driven, collaborative interactions and, most importantly, it may provide the means for teams and agencies to evaluate the cloud computing model in their specific context, with minimal infrastructure changes, and before committing to a specific cloud services provider.

cloud computing↗

National Campaign Partner Demonstration Team Annual Review April 2023

- NASA developed the Advanced Air Mobility Project (AAM) and the National Campaign (NC) series to identify and address challenges ahead for advanced air mobility concepts. - NC seeks to challenge industry as follows; - Execute progressively more difficult ecosystem-wide system-level safety and integration scenarios - Demonstrate practical and scalable system concepts - Build a knowledge base for development of requirements and standards - There are currently three focus areas within the NASA AAM NC Portfolio - Vehicle Development and Operations: test and inform capabilities that are critical enablers for AAM such as electric aircraft propulsion and increasing levels of automation - Airspace Design and Operations: develop and validate an operational concept to integrate and manage AAM traffic safely and efficiently - Community Integration: understand and address critical barriers to community integration, such as public acceptance (noise, security, privacy, etc.), supporting infrastructure, and local regulation

Eric N Becker↗

Development of an end state vision to implement digital monitoring in nuclear plants

Transitioning from an onsite Maintenance & Diagnostics Center to cloud-based services offers many new opportunities with computing power and storage, but also new challenges in terms of networking and security. This report will cover everything required for that transition including data processing and uploading to cloud services, feature selection, model creation, and result visualization for decision making. Although there are several other cloud-based services (e.g. Amazon Web Services and Google Cloud), this report explores Microsoft Azure to simplify nomenclature and maintain a consistent focus. Many of the services offered by Microsoft Azure are also available in the other cloud-based services, and their differences have been recorded in other literature. The Azure services most important to a nuclear power plant including networking & security, storage & databases, and Artificial Intelligence (AI) are reviewed here. Networking covers all aspects related to communication to Azure resources including security, privacy, and redundancy. Storage & databases includes data storage, upgrading, patching, backups, and monitoring. The AI services allows the user access to the machine learning (ML) techniques developed with Azure including automated ML, anomaly detection, computer vision, and natural language processing. This report summaries the features, capabilities, and challenges when using cloud-based services in a user-friendly manner.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

Air Traffic Management Blockchain Infrastructure for Security, Authentication, and Privacy

Current radar-based air traffic service providers may preserve privacy for military and corporate operations by procedurally preventing public release of selected flight plans, position, and state data. The FAA mandate for national adoption of Automatic Dependent Surveillance Broadcast (ADS-B) in 2020 does not include provisions for maintaining these same aircraft-privacy options, nor does it address the potential for spoofing, denial of service, and other well-documented risk factors. This paper presents an engineering prototype that embodies a design and method that may be applied to mitigate these ADS-B security issues. The design innovation is the use of an open source permissioned blockchain framework to enable aircraft privacy and anonymity while providing a secure and efficient method for communication with Air Traffic Services, Operations Support, or other authorized entities. This framework features certificate authority, smart contract support, and higher-bandwidth communication channels for private information that may be used for secure communication between any specific aircraft and any particular authorized member, sharing data in accordance with the terms specified in the form of smart contracts. The prototype demonstrates how this method can be economically and rapidly deployed in a scalable modular environment.

air traffic privacy & authentication↗

Air Traffic Management Blockchain Infrastructure for Security, Authentication, and Privacy

Current radar-based air traffic service providers may preserve privacy for military and corporate operations by procedurally preventing public release of selected flight plans, position, and state data. The FAA mandate for national adoption of Automatic Dependent Surveillance Broadcast (ADS-B) in 2020 does not include provisions for maintaining these same aircraft-privacy options, nor does it address the potential for spoofing, denial of service, and other well-documented risk factors. This paper presents an engineering prototype that embodies a design and method that may be applied to mitigate these ADS-B security issues. The design innovation is the use of an open source permissioned blockchain framework to enable aircraft privacy and anonymity while providing a secure and efficient method for communication with Air Traffic Services, Operations Support, or other authorized entities. This framework features certificate authority, smart contract support, and higher-bandwidth communication channels for private information that may be used for secure communication between any specific aircraft and any particular authorized member, sharing data in accordance with the terms specified in the form of smart contracts. The prototype demonstrates how this method can be economically and rapidly deployed in a scalable modular environment.

ADS-B cybersecurity↗

Transactive Energy System Deployment Over Insecure Communication Links

Here, in this paper, the privacy and security issues associated with the transactive energy system (TES) deployment over insecure communication links are addressed. In particular, it is ensured that 1) individual agents’ bidding information is kept private throughout hierarchical market-based interactions; and 2) any extraneous data injection attack can be quickly and easily detected. An implementation framework is proposed to enable the cryptography-based enhancement of privacy and security for the deployment of any general hierarchical systems including TESs. Under the proposed framework, a unified cryptography-based approach is developed to achieve both privacy and security simultaneously. Specifically, privacy preservation is realized by an enhanced Paillier encryption scheme, where a block design is proposed to significantly improve computational efficiency. Attack detection is further achieved by an enhanced Paillier digital signature scheme, where a stamp-concatenation mechanism is proposed to enable detection of data replace and reorder attacks. Simulation results verify the effectiveness of the proposed cyber-resilient design for transactive energy systems. Note to Practitioners—This paper is motivated by addressing the issues of cyber resiliency for practically deploying transactive energy system (TES) but it is also applicable to the problem of enhancing the privacy and security for any general hierarchical control systems. TES is an emerging control approach that engages energy suppliers and customers through market operations and uses the price to optimally allocate energy resources. While it has been shown to be promising for power system applications, the underlying market-based interactions raise significant concerns of privacy (data leakage) and security (data tampering). However, existing TES works only focus on the coordination mechanism instead of privacy and security issues. This paper proposes a new cryptography-based TES design for practical deployment. Specifically, to protect privacy, individual supply and demand amounts to be exchanged are all encrypted in a particular way such that the original amounts cannot be inferred from the encrypted amounts, while the desired computation for setting the market clearing price can be carried out over the encrypted amounts, thus generating an encrypted result which, when decrypted, matches that of the same computation over the original amounts. To achieve security, for each exchanged data, its sender generates a particular digital signature which is exchanged together with the data. This enables the receiver to automatically detect the integrity by checking whether a mathematical relationship holds for the pair of data and signature. In our future research, we will investigate more challenging scenarios where some suppliers and customers themselves could be corrupted and purposely submit distorted amounts.

97 MATHEMATICS AND COMPUTING↗

Managing Cyber Risk: from the Ground to the Air and Beyond Out There

Experts from the aerospace sector with the focus of presenting current state-of-the-art in aviation cyber security and discussing major challenges, requirements, and developments. A variety of topics will be addressed by the panel, including: Aviation cyber security regulations, standards, and best practices Aviation information sharing and analysis challenges Aircraft systems and avionics cyber security challenges Airline and airport stakeholder cyber perspectives CNSATM cyber security challenges UAS cyber security and privacy requirements Military aviation cyber security issues in the NAS

Davis, Jerry L.↗