Search NASASearch

SEARCH · Search NASA

Results for “zero trust”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

Accessible Telemetry Streams using a Zero Trust Architecture for the Flight Operations Directorate

As a result of information technology based work becoming increasingly distributed, unique challenges have been presented within the realm of defined network perimeters, namely with respect to secure access to resources. Historically, and from a simplistic abstract perspective, the common approach has been to adopt the, so-called, moat model whereby a physical network perimeter (or interconnected perimeters) is defined to encapsulate resources behind a boundary protected by a firewall. Users are provisioned access through a virtual private network (VPN) and may be further constrained to resources through specific firewall allow and disallow rulesets. Virtual Private Networks and firewall rulesets lead to common problems, particularly at scale and, as a result, perimeter-less architectures provided over the public internet are increasingly becoming prevalent, particularly with its more popular implementation, the Zero Trust Architecture. We present a proposed implementation of the Zero Trust Architecture with a particular concrete example utilizing a de-perimeterized network that requires authentication and authorization for each action between nodes and does not operate within an implicit trust boundary. It should be noted that this paper is not an attempt at providing comprehensive resolutions for the specific problem space with respect to perimeter based security and is more directed at providing information with regard to our proposed implementation of a Zero Trust Architecture for the Flight Operations Directorate. We direct the reader to our Introduction and Background section for more details on specific documentation and where it can be located as it relates to de-perimeterization and Zero Trust.

Paul Shoemaker

Zero Trust and Identity Access Management in Support of Service-Based Urban Air Mobility Applications

Urban Air Mobility environments will contain of a collection of service-based services, which will be typically hosted within cloud infrastructures. The underlying data for these UAM services will need to be secured. One approach to securing these UAM services would be to leverage the Zero Trust framework, that focuses on securing services and associated data, instead of securing the network. An early step in moving towards a Zero Trust framework is to standardize identity access manage support for an ever-widening set of services, where users must explicitly be granted access to each service.

UAM

Zero-Trust Architecture for Autonomous Edge Computing

We are at the apex of an aviation revolution where autonomy will play a central role in enabling complex, multi-agent systems to communicate, interact, and collaborate on a myriad of applications spanning autonomous swarms to wild-fire management. Autonomy is not an absolute but rather a spectrum ranging from a system requiring significant human intervention to one requiring little to none [1]. For example, the extreme, in the case of an autonomous aircraft, is one that operates independently in the airspace interacting with all other elements (air traffic controllers, other pilots) as if it were a human pilot. Critical to this vision is an architecture that enables autonomous agents to interact with minimal latency. Edge computing is an emerging architecture where compute and storage is pushed to the ‘edge’ of the network in order to minimize the round-trip time from agent to resource thereby mitigating the latency associated with cloud-only based approaches. Additionally, services can generate massive amounts of data (e.g., video feeds), which may require analysis in near real-time. Moving this data to the cloud for further processing may not be feasible due to latency, bandwidth, and cost. Privacy, security, and reliability can also be improved by edge computing architectures. However, this geo-distributed and dynamic* architecture complicates the establishment of unambiguous network security boundaries and can lead to vulnerabilities including man in the middle attacks, replay attacks, physical security breaches of edge nodes, signal interception, etc. This motivates the need for zero-trust architectures [2–4] which de-emphasize the notion of static network perimeters and, as the name implies, do not instill any innate trust in any particular agent. It is required that all agents must be authorized and approved in every transaction. In this paper, we present a zero-trust architecture suitable for edge-computing applications that demand significant low-latency, security, privacy, and reliability.

zero trust

Zero Trust Network Security

A poster for the Pathways Student Showcase that includes a description of what Zero Trust Network Security is, the rough timeline for the initial stages of implementation here at KSC, who I am, and what I'm working on.

Coulter, Lawrence W.

An explicit solution to the optimal LQG problem for flexible structures with collocated rate sensors

We present a class of compensators in explicit form (not requiring numerical computer calculations) for stabilizing flexible structures with collocated rate sensors. They are based on the explicit solution, valid for both Continuum and FEM Models, of the LQG problem for minimizing mean square rate. They are robust with respect to system stability (will not destabilize modes even with mismatch of parameters), can be instrumented in state space form suitable for digital controllers, and can be specified directly from the structure modes and mode 'signature' (displacement vectors at sensor locations). Some simulation results are presented for the NASA LaRC Phase-Zero Evolutionary Model - a modal Trust model with 86 modes - showing damping ratios attainable as a function of compensator design parameters and complexity.

Balakrishnan, A. V.

Estimating Future Changes of Energy Demand for Heating and Cooling Buildings at NASA Centers GC23J-1198

With its unique and trusted earth observations, NASA is a critical source in informing decisions that will help achieve the U.S. goal of Net-Zero Greenhouse Gas (GHG) Emissions by 2050. NASA’s Prediction of Worldwide Energy Resource (POWER) project facilitates the use of NASA Earth Science data holdings within the energy, agricultural, and building heating/cooling design industries. POWER packages solar and meteorological data from several NASA projects in a user friendly GIS-enabled web services system (https://power.larc.nasa.gov). As part of the development of new data products to support the energy and building heating/cooling design communities, we estimate the changes in energy required to heat and cool buildings in the future climate at 14 different NASA site locations spread throughout the continental United States, as projected by CMIP6 climate models under different emissions scenarios. Bias-corrected downscaled time series of meteorological variables are taken from NASA Earth Exchange (NEX) Global Daily Downscaled Projections (GDDP-CMIP6) downscaled climate model data. The spread between the different model projections is accounted for by analyzing both the ensemble average of 22 CMIP6 models and 6 representative models with different climate sensitivities and different interannual variability. Changes in energy use are estimated in two ways. First, changes in the total annual heating and cooling degree days (HDD and CDD, respectively) are calculated relative to the current climate. This is done at all 14 sites. Second, the downscaled time series are used as inputs into RETScreen(R), a clean energy management decision tool, to give an estimate of heating/cooling energy use for a typical office building. We use this estimation method with model data at Langley Research Center. In the next 50 years, the annual total of HDD (CDD) is projected to decrease by 8-38% (increase by 5-28%) at all sites, with the increase in CDD typically a larger magnitude the decrease in HDD. For a typical small office building at Langley Research Center, the amount of energy needed to cool increases by 33-54% and the amount of energy to heat decreases by 29-40%. POWER is working to develop long term climate data services based on these results to include in future data products to provide to users.

Bradley M. Hegyi

Development and Deployment of Robonaut 2 to the International Space Station

The development of the Robonaut 2 (R2) system was a joint endeavor with NASA and General Motors, producing robots strong enough to do work, yet safe enough to be trusted to work near humans. To date two R2 units have been produced, designated as R2A and R2B. This follows more than a decade of work on the Robonaut 1 units that produced advances in dexterity, tele-presence, remote supervision across time delay, combining mobility with manipulation, human-robot interaction, force control and autonomous grasping. Design challenges for the R2 included higher speed, smaller packaging, more dexterous fingers, more sensitive perception, soft drivetrain design, and the overall implementation of a system software approach for human safety, At the time of this writing the R2B unit was poised for launch to the International Space Station (ISS) aboard STS-133. R2 will be the first humanoid robot in space, and is arguably the most sophisticated robot in the world, bringing NASA into the 21st century as the world's leader in this field. Joining the other robots already on ISS, the station is now an exciting lab for robot experiments and utilization. A particular challenge for this project has been the design and certification of the robot and its software for work near humans. The 3 layer software systems will be described, and the path to ISS certification will be reviewed. R2 will go through a series of ISS checkout tests during 2011. A taskboard was shipped with the robot that will be used to compare R2B's dexterous manipulation in zero gravity with the ground robot s ability to handle similar objects in Earth s gravity. R2's taskboard has panels with increasingly difficult tasks, starting with switches, progressing to connectors and eventually handling softgoods. The taskboard is modular, and new interfaces and experiments will be built up using equipment already on ISS. Since the objective is to test R2 performing tasks with human interfaces, hardware abounds on ISS and the crew will be involved to help select tasks that are dull, dirty or dangerous. Future plans for R2 include a series of upgrades, evolving from static IVA (Intravehicular Activity) operations, to mobile IVA, then EVA (Extravehicular Activity).

Ambrose, Robert O.