Search NASA⌕ Search

SEARCH · Search NASA

Results for “trusted execution environments”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

Performance Analysis of Scientific Computing Workloads on Trusted Execution Environments

Scientific computing sometimes involves computation on sensitive data. Depending on the data and the execution environment, the HPC (high-performance computing) user or data provider may require confidentiality and/or integrity guarantees. To study the applicability of hardware-based trusted execution environments (TEEs) to enable secure scientific computing, we deeply analyze the performance impact of AMD SEV and Intel SGX for diverse HPC benchmarks including traditional scientific computing, machine learning, graph analytics, and emerging scientific computing workloads. We observe three main findings: 1) SEV requires careful memory placement on large scale NUMA machines (1x -3.4x slowdown without and 1x -1.15x slowdown with NUMA aware placement), 2) virtualization - a prerequisite for SEV - results in performance degradation for workloads with irregular memory accesses and large working sets (1x -4x slowdown compared to native execution for graph applications) and 3) SGX is inappropriate for HPC given its limited secure memory size and inflexible programming model (1.2x -126x slowdown over unsecure execution). Finally, we discuss forthcoming new TEE designs and their potential impact on scientific computing.

97 MATHEMATICS AND COMPUTING↗

Enabling Design Space Exploration for RISC-V Secure Compute Environments

Cycle-level architectural simulation of Trusted Execution Environments (TEEs) can enable extensive design space exploration of these secure architectures. Existing architectural simulators which support TEEs are either based on hardware-level implementations or abstract analytic models. In this paper, we describe the implementation of the gem5 models necessary to run and evaluate the RISC- V-based open source TEE, Keystone, and we discuss how this simulation environment opens new avenues for designing and studying these trusted environments. We show that the Keystone simulations on gem5 exhibit similar performance as the previous hardware evaluations of Keystone. We also describe three simple example use cases (understanding the reason of trusted execution slowdown, performance of memory encryption, and micro-architecture impact on trusted execution performance) to demonstrate how the ability to simulate TEEs can provide useful information about their behavior in the existing form and also with enhanced designs.

97 MATHEMATICS AND COMPUTING↗

Regression Analysis with the Directed Infusion of Data

Integrating artificial intelligence and machine learning tools into industry necessitates large-scale collaborative efforts that ensure the robust and accurate execution of downstream analytics such as time series prediction, uncertainty quantification, grid optimization, and condition monitoring. However, concerns related to data privacy pervade the nuclear industry due to the proprietary nature of its data and the possibility of data leakage. Legacy techniques such as encryption often require the explicit transmission of data to trustworthy parties, thereby inviting data leakage concerns. The ideal collaboration scenario avoids the explicit dissemination of data/code while maintaining experimental fidelity, which is currently accomplished using various techniques such as trusted execution environments, homomorphic encryption, differential privacy, and multimatrix masking. These techniques, however, often necessitate a trade-off between trust, efficiency, and utility. This article extends a previously proposed technique called the directed infusion of data (DIOD) that ensures data privacy, allows for scalable obfuscation, and combats the risk of data leakage without compromising utility. The experiments discussed in this article examine a regression-type scenario using DIOD with the goal of preserving the inferential link between two variables. Using the point-kinetics equations, regression experiments compare the performance of a model trained using the original data to that of a model trained using the obfuscated data, which produced identical results. Our claim is further strengthened by an information theoretic proof and experiment, which showed that the inferential content between variables remains the same after obfuscation, thereby avoiding the required communication of the proprietary data.

47 - OTHER INSTRUMENTATION↗

CROWBAR: Natively Fuzzing Trusted Applications Using ARM CoreSight

Abstract Trusted execution environments (TEE) are deployed on many platforms to provide both confidentiality and integrity, and their extensive use offers a secure environment for privacy-sensitive operations. Despite TEE prevalence in the smartphone and tablet market, vulnerability research into TEE security is relatively rare. This is, in part, due to the strong isolation guarantees provided by its implementation. In this paper, we propose a hardware assisted fuzzing framework, CROWBAR, that bypasses TEE isolation to natively evaluate trusted applications (TAs) on mobile devices by leveraging ARM CoreSight components. CROWBAR performs feedback-driven fuzzing on commercial, closed source TAs while running in a TEE protected environment. We implement CROWBAR on 2 prototype commercial-off-the-shelf (COTS) smartphones and one development board, finding 3 unique crashes in 5 closed source TAs that are previously unreported in the TrustZone fuzzing literature.

Shan, Haoqi↗

Remediation of Temporary Storage Sites in Support of the Port Hope Area Initiative - 20295

The Port Hope Area Initiative is a community-based solution for the long-term management of historic low level radioactive waste (LLRW) resulting from 60 years of uranium and radium processing operations in the Town of Port Hope which is located in Ontario, Canada. The Eldorado refinery, on the north shore of Lake Ontario, began refining radium-226 from pitchblende ore, later transitioning to the refining of uranium. Through the history of the operation, LLRW was deposited throughout the town of Port Hope as a result of fugitive emissions from the plant and/or through the re-use of process residues as building material and backfill. Historical clean-up activities conducted in the late 1970's involved the remediation of approximately 400 properties and the relocation of 100,000 cubic metres of contaminated soil to a disposal facility in Chalk River operated by Atomic Energy of Canada Limited (AECL). Owing to space limitations at that disposal facility, any LLRW identified through construction monitoring since that time has been stored in the community at three temporary storage sites located throughout the town. These include: the Centre Pier mound that contained approximately of 19,800 m{sup 3} of LLRW-impacted soil that originated from the construction of a new water treatment plant; two mounds located at a licensed storage facility containing LLRW obtained from residential clean-up activities (11,000 m{sup 3}); and a small pad adjacent to the municipal sewage treatment plant containing 2200 m{sup 3} of LLRW-containing sludge. With the construction of a new long-term waste management facility (LTWMF) that has been designed to house all of the LLRW identified within Port Hope, the three sites were early candidates for remediation. The clean-up of the three temporary storage sites was a significant milestone for the Port Hope Area Initiative. After a decade of planning and consultation, this work represents the first sites in the municipality to be remediated with the waste being safety removed and transferred to the newly constructed LTWMF. This paper discusses the challenges associated with the clean-up activities for these three sites and the strategies employed to address those challenges. These included weather-related challenges, owing to the seasons over which the work was conducted as well as those associated with working within a closely-knit community. Canadian Nuclear Laboratories (CNL), working on behalf of the federal government, has worked diligently to develop a positive and trusting relationship with the community. Consequently, the successful execution of this project needed to be sensitive to, and respectful of the needs of the community. In addition to the usual Health, Safety and Environment training, project staff received community awareness training that spoke to the history of this community-based initiative and the expected behavior when working within the community. Transportation routes were defined based on safety and the need to minimize disruption to local traffic while haul-times where scheduled around school bus hours to enhance public safety. The successful completion of this first of many remediation projects to be completed under the Port Hope Area Initiative reflected years of careful planning. Nevertheless, there were a number of 'lessons learned' that have been applied on other ongoing projects be completed under the Port Hope Area Initiative. (authors)

12 MANAGEMENT OF RADIOACTIVE AND NON-RADIOACTIVE W↗

Security Evaluation of Smart Cards and Secure Tokens: Benefits and Drawbacks for Reducing Supply Chain Risks of Nuclear Power Plants

The supply chain attack pathway is being increasingly used by adversaries to bypass security controls and gain unauthorized access to sensitive networks and equipment (e.g., Critical Digital Assets). Cyber-attacks targeting supply chain generally aim to compromise the environments, products, or services of vendors and suppliers to inject, add, or substitute authentic software and hardware with malicious elements. These malicious elements are deemed to be authentic as they arise from the vendor or supplier (i.e., the supply chain). This research aims to leverage findings and assumptions made from the previous report to determine the security benefits and drawbacks of a smart card- based hardware root of trust. Smart cards can provide devices inside Nuclear Power Plants (NPP) with a secure environment to store keys in and perform sensitive operations such as digital signature generation. These abilities can be leveraged to increase supply chain cybersecurity by autonomously providing NPP Licensees with reports on device integrity, authenticity and measurements of executable and non-executable data.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Blockchain-Enabled Secure Device-to-Device Communication in Software-Defined Networking

The Internet of Things (IoT) continues to increase the demand for seamless communication among IoT devices. The rapid growth of IoT devices has led to an exponential increase in device-to-device (D2D) communication within the Software-Defined Networking (SDN), though it enables a flexible archi-tecture for managing network resources. However, traditional security models face challenges (e.g., Security, privacy, and trust) in addressing the dynamic and decentralized nature of these communications. Despite of these challenges, this paper proposes a novel approach that leverages blockchain technology to enhance the security, privacy, and trustworthiness of D2D communication within an SDN environment. The proposed approach integrates blockchain nodes in sDN components to establish a decentralized ledger for transparent and verifiable records. Smart contracts enforce authentication rules to ensure that only authenticated devices can access the network and engage in transactions securely. It also automates the security policies to ensure temper resistance execution using the cryptographic mechanism for data integrity and authentic communication. The Implementation of the proposed algorithms validates the resilience of the proposed approach against cyberattacks. Overall, the proposed approach enables efficient and secure D2D communication for resilient SDN infrastructure in IoT ecosystems.

Das, Debashis↗

Building and Executing Aggressive Research Plans in a Large National Laboratory Consortium: Insights from the Co-Optimization of Fuels and Engines Initiative

This report describes lessons learned in the establishment, execution and termination of a large, multi-institutional consortium, derived from the Co-Optimization of Fuels and Engines experience. The decision to form a consortium comes with benefits (in advancing challenging multidisciplinary research) and costs (in time and additional management funds). Once the decision is made, key elements to a strong start include establishing a shared vision and goals; engaging an experienced project manager early; instituting feedback and oversight mechanisms to ensure relevance, strong performance, and situational awareness. Once a consortium is up and running, DOE and leadership should strike the right balance between competition and collaboration; foster an environment that builds trust; and adjust the organizational structure as needed to maintain collaboration. Finally, DOE and the labs can plan effectively for a smooth transition as a consortium winds down. This report provides some additional lessons and details on these lessons that we hope future DOE and lab leaders will find useful as they contemplate standing up new consortia.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Zero Trust Strategies for Chemical, Biological, Radiological, and Nuclear Detection Systems: D.1 Cyber Scenarios

The evolving landscape of cybersecurity necessitates a paradigm shift to a Zero Trust (ZT) model, which assumes breaches and continuously verifies trust. This approach reshapes how trust boundaries are established, focusing on identities, devices, networks, applications, and data, rather than solely relying on perimeter defenses such as firewalls. Central to this transformation is the National Institute of Standards and Technology's (NIST) Special Publication 800-207, outlining the Zero Trust Architecture (ZTA), along with Executive Order 14028, which mandates federal agencies to adopt ZT principles. Complementary to these efforts, the Cybersecurity and Infrastructure Security Agency (CISA) developed the Zero Trust Maturity Model (ZTMM), providing a framework with five pillars and three cross-cutting capabilities to guide agencies toward enhanced cybersecurity maturity. In support of these initiatives, the DHS Countering Weapons of Mass Destruction Office (CWMD) is applying ZT principles to secure Chemical, Biological, Radiological, and Nuclear (CBRN) detection systems. Recognizing the diverse deployment models and network connectivity of these systems—from stationary, non-networked units to mobile, cloud-connected devices—the Pacific Northwest National Laboratory (PNNL) is developing cybersecurity scenarios specifically for CBRN environments. These scenarios examine various configurations and technological capabilities, offering insights into the application of ZTMM pillars in enhancing the security postures of CBRN devices. The cybersecurity scenarios presented by PNNL are hypothetical, crafted to explore theoretical situations and stimulate discussion on the potential use or compromise of CBRN detection systems in varied contexts. These narratives are illustrative and do not reference any real events or actual networks. Instead, they employ generalized reference models to highlight concepts and potential issues within CBRN security, focusing on how Zero Trust strategies can be adapted to address these challenges effectively.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

DOE BSSD Performance Management Metrics Report Q2

The vision of the National Microbiome Data Collaborative (NMDC) centers on the concept of connecting data, people, and ideas to advance microbiome innovation and discovery. Building data infrastructure, while key to NMDC’s ability to execute on our vision, can only go so far in creating scientific impact. By fostering strong community partnerships and developing a set of robust community outreach and training programs, we are able to turn our products – the Submission Portal, NMDC EDGE, and the Data Portal – into tools that empower the scientific community. Our multi-pronged community building approach spans individual researchers, research teams, consortia and scientific societies, and institutions and federal agencies. To foster a collaborative and inclusive community-centered environment, we have identified three strategic objectives to promote an inclusive and connected community: (1) recognize and support the diverse research needs and perspectives of the microbiome research community; (2) promote best practices across the microbiome community, from researchers to funders, through community-driven practices (FAIR, CARE, and TRUST); and (3) build a microbiome ecosystem that enables scientific discovery and innovation across stakeholders. These strategic objectives allow our team to focus on impact across a diverse range of activities, from launching the American Society for Microbiology (ASM) Microbiome Data Prize to supporting the Ambassador and Champions programs fostering learning and building a collaborative network. We broadly communicate our work through social media (X/Twitter, LinkedIn, and Instagram), The Microbiome Standard (our quarterly newsletter), and Annual Reports. All our work is underpinned by a strong commitment to diversity, equity, and inclusion as articulated in our Action Plan that tracks progress towards key metrics. A core component of our engagement strategy is user research. User research ensures the Submission Portal, NMDC EDGE, Data Portal, and the new Field Notes mobile app are designed with and for the scientific community. Our user research efforts consist of asking researchers exploratory questions to collect information on researcher priorities, methodologies, and perceptions to ensure that we are aware of the current state of microbiome research. Our usability testing provides researchers with prototypes or test environments of the NMDC products, and we capture valuable information on how users interact with the products to make improvements. Given the diverse nature of microbiome work, we acknowledge that we are not aware of all pressing data challenges and thus rely on the research community to help us identify the most important issues to prioritize. To date, we have conducted 24 interviews and one beta-testing call with 10 participants across all NMDC products, which have generated 321 insights and 120 action items. Herein, we describe the ways we engage with the microbiome research community to advance the NMDC mission.

59 BASIC BIOLOGICAL SCIENCES↗