Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Network Security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 199 records · Page 11

IRI Technology Landscape – A survey of re-usable components and methodologies

This document describes technical implementation details on network access schemes connecting API-driven workflows to supercomputer centers. API-driven workflows are a central theme in connected computing, since they bring the terminal-mainframe' access pattern present since the 1970s up to the task of interfacing with modern web browser technologies. Both security (HTTPS/TLS/IPSec/VPNs/public key cryptography/digital signatures) and network protocol stacks (HTTP-REST APIs, tokens, gRPC, SRTP) have evolved to the point where implementing API-driven workflows is possible using stable, secure off-the-shelf software.

97 MATHEMATICS AND COMPUTING↗

Enabling Innovation and Collaboration Across Geography and Culture: A Case Study of NASA's Systems Engineering Community of Practice

In 2004, NASA faced major knowledge sharing challenges due to geographically isolated field centers that inhibited personnel from sharing experiences and ideas. Mission failures and new directions for the agency demanded better collaborative tools. In addition, with the push to send astronauts back to the moon and to Mars, NASA recognized that systems engineering would have to improve across the agency. Of the ten field centers, seven had not built a spacecraft in over 30 years, and had lost systems engineering expertise. The Systems Engineering Community of Practice came together to capture the knowledge of its members using the suite of collaborative tools provided by the NASA Engineering Network (NEN.) The NEN provided a secure collaboration space for over 60 practitioners across the agency to assemble and review a NASA systems engineering handbook. Once the handbook was complete, they used the open community area to disseminate it. This case study explores both the technology and the social networking that made the community possible, describes technological approaches that facilitated rapid setup and low maintenance, provides best practices that other organizations could adopt, and discusses the vision for how this community will continue to collaborate across the field centers to benefit the agency as it continues exploring the solar system.

NEN↗

Malcolm Deployment Guide for Solar Power Generation Plants

This guide provides detailed instructions for deploying Malcolm in Solar Power Generation systems. It covers the deployment process, from understanding the network architecture of these systems to configuring network switches and Switched Port Analyzer (SPAN) ports or mirror ports or TAPs. The guide also includes best practices for deploying Hedgehog sensors, another critical component in these systems. Following this guide, users can enhance network visibility, improve their system’s security, and effectively troubleshoot common issues.

14 SOLAR ENERGY↗

DEVELOPMENT OF AN INTEGRATED SECURITY AND SAFETY MONITORING SYSTEM FOR SPENT NUCLEAR FUEL AND HIGH-LEVEL WASTE TRANSPORTATION

This paper provides an overview of the progress to date, and discussion of the path forward, related to designing, fabricating, and testing an integrated security and safety monitoring system (ISSMS) for railcars used to transport spent nuclear fuel (SNF) and high-level radioactive waste (HLW) in the United States. The system will comply with the US Department of Energy’s (DOE) Order 460.2B “Departmental Materials Transportation Management” and the Association of American Railroads’ (AAR) standard S-2043 “Performance Specification for Trains Used to Carry High-level Radioactive Material” [1] developed specifically for railcars used to transport high-level radioactive material (HLRM). DOE is in the process of developing and testing an ISSMS that will satisfy both DOE requirements and AAR standards. DOE has already developed railcar designs for transportation of HLRM. In 2024, DOE’s Atlas railcar project completed the design, fabrication and testing of three railcar types: transportation cask-carrying, buffer, and security escort, resulting in AAR conditional approval to operate on freight rail networks in North America. DOE decided to combine the required security and safety systems into one system, and this combined system is the subject of the current effort. DOE is developing and proposes to implement the ISSMS for these railcars as part of the build out of the railcar fleet. DOE began planning for development of the ISSMS in February 2020. The project is divided into seven phases starting with conceptual design and continuing through production design, as shown in Figure 1. An earlier version of the system was tested as part of the Atlas railcar consist demonstration test run in 2023. This paper describes the design features and system testing using the Atlas project railcars, and laboratory testing completed to date. The paper will also describe the activities planned to support the DOE project to ship the High Burn-Up Research Cask (HBRC) in 2027.

Schultze, Michael [ORNL] (ORCID:0000000283205671)↗

User Needs and Advances in Space Wireless Sensing and Communications

Decades of space exploration and technology trends for future missions show the need for new approaches in space/planetary sensor networks, observatories, internetworking, and communications/data delivery to Earth. The User Needs to be discussed in this talk includes interviews with several scientists and reviews of mission concepts for the next generation of sensors, observatories, and planetary surface missions. These observatories, sensors are envisioned to operate in extreme environments, with advanced autonomy, whereby sometimes communication to Earth is intermittent and delayed. These sensor nodes require software defined networking capabilities in order to learn and adapt to the environment, collect science data, internetwork, and communicate. Also, some user cases require the level of intelligence to manage network functions (either as a host), mobility, security, and interface data to the physical radio/optical layer. For instance, on a planetary surface, autonomous sensor nodes would create their own ad-hoc network, with some nodes handling communication capabilities between the wireless sensor networks and orbiting relay satellites. A section of this talk will cover the advances in space communication and internetworking to support future space missions. NASA's Space Communications and Navigation (SCaN) program continues to evolve with the development of optical communication, a new vision of the integrated network architecture with more capabilities, and the adoption of CCSDS space internetworking protocols. Advances in wireless communications hardware and electronics have enabled software defined networking (DVB-S2, VCM, ACM, DTN, Ad hoc, etc.) protocols for improved wireless communication and network management. Developing technologies to fulfil these user needs for wireless communications and adoption of standardized communication/internetworking protocols will be a huge benefit to future planetary missions, space observatories, and manned missions to other planets.

Kegege, Obadiah↗

Management of the Space Physics Analysis Network (SPAN)

Here, the purpose is to define the operational management structure and to delineate the responsibilities of key Space Physics Analysis Network (SPAN) individuals. The management structure must take into account the large NASA and ESA science research community by giving them a major voice in the operation of the system. Appropriate NASA and ESA interfaces must be provided so that there will be adequate communications facilities available when needed. Responsibilities are delineated for the Advisory Committee, the Steering Committee, the Project Scientist, the Project Manager, the SPAN Security Manager, the Internetwork Manager, the Network Operations Manager, the Remote Site Manager, and others.

Green, James L.↗

Operational Concepts for a Generic Space Exploration Communication Network Architecture

This document is one of three. It describes the Operational Concept (OpsCon) for a generic space exploration communication architecture. The purpose of this particular document is to identify communication flows and data types. Two other documents accompany this document, a security policy profile and a communication architecture document. The operational concepts should be read first followed by the security policy profile and then the architecture document. The overall goal is to design a generic space exploration communication network architecture that is affordable, deployable, maintainable, securable, evolvable, reliable, and adaptable. The architecture should also require limited reconfiguration throughout system development and deployment. System deployment includes: subsystem development in a factory setting, system integration in a laboratory setting, launch preparation, launch, and deployment and operation in space.

networking↗

Economical Ground Data Delivery

Data delivery in the Deep Space Network (DSN) involves transmission of a small amount of constant, high-priority traffic and a large amount of bursty, low-priority data. The bursty traffic may be initially buffered and then metered back slowly as bandwidth becomes available. Today both types of data are transmitted over dedicated leased circuits. The authors investigated the potential of saving money by designing a hybrid communucations architecture that uses leased circuits for high-priority network communications and dial-up circuits for low-priority traffic. The architecture presented here may also be applied to any ground station-to-customer network within the range of a common carrier. The authors compare estimated costs for various scenerios and suggest security safeguards that should be considered.

communications↗

Efficient Reformulation and Optimization for SC-ACOPF with Line Switching

This project aims to develop efficient and robust computational methods for solving the security-constrained alternating current optimal power flow problem (SC-ACOPF). The SC-ACOPF problem is a central problem in operating the electric power grids in the United States. It determines the most economically efficient way to operate the generation and transmission system to meet daily electricity demand. The solution found by solving an SC-ACOPF problem must satisfy the physics of the alternating current (AC) power flows, various generator and network operational constraints, and must maintain secure operation under various contingency scenarios, where a generator, a transmission branch, or a transformer may unexpectedly trip offline.

97 MATHEMATICS AND COMPUTING↗

Famine Early Warning Systems Network (FEWS NET) Land Data Assimilation System (LDAS) and Other Assimilated Hydrological Data at NASA GES DISC

The NASA Goddard Earth Sciences Data and Information Services Center (GES DISC) provides science support for several data sets relevant to agriculture and food security, including the Famine Early Warning Systems Network (FEWS NET) Land Data Assimilation System (LDAS), or FLDAS data set. The GES DISC is one of twelve NASA Earth Observing System (EOS) data centers that process, archive, document, and distribute data from Earth science missions and related projects. The GES DISC hosts a wide range of remote sensing and model data, and provides reliable and robust data access and other services to users worldwide. Beyond data archive and access, the GES DISC offers many services to visualize and analyze the data. This presentation provides a summary of the hydrological data available at the GES DISC, along with an overview of related data services. Specifically, the FLDAS data set has been adapted to work with domains, data streams, and monitoring and forecast requirements associated with food security assessment in data-sparse, developing country settings. The FLDAS global monthly data have a 0.1 x 0.1 degree spatial resolution covering the period from January 1982 to present. Global FLDAS monthly anomaly and monthly climatology data are also available at the GES DISC to evaluate how current conditions compare to averages over the FLDAS 35-year period. Several case studies using the FLDAS soil moisture, evapotranspiration, rainfall, runoff, and surface temperature data will be presented.

Loeser, Carlee↗

Securing the Global Airspace System Via Identity-Based Security

Current telecommunications systems have very good security architectures that include authentication and authorization as well as accounting. These three features enable an edge system to obtain access into a radio communication network, request specific Quality-of-Service (QoS) requirements and ensure proper billing for service. Furthermore, the links are secure. Widely used telecommunication technologies are Long Term Evolution (LTE) and Worldwide Interoperability for Microwave Access (WiMAX) This paper provides a system-level view of network-centric operations for the global airspace system and the problems and issues with deploying new technologies into the system. The paper then focuses on applying the basic security architectures of commercial telecommunication systems and deployment of federated Authentication, Authorization and Accounting systems to provide a scalable, evolvable reliable and maintainable solution to enable a globally deployable identity-based secure airspace system.

Communications↗

Network Slicing for Federated Learning in Operational Technology Environment

Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) environments are essential to modern infrastructure, facing challenges in ensuring low-latency, high-throughput communication while mitigating cyber threats. This paper presents a framework integrating Federated Learning (FL) and network slicing with Quality of Service (QoS) to enable real-time monitoring without disrupting OT operations. Leveraging digital twin technology and Network Function Virtualization (NFV), the architecture supports predictive analytics and Industry 4.0 requirements. FL facilitates decentralized model training, preserving data privacy and scalability, though it introduces potential throughput constraints. Network slicing addresses this by creating dedicated virtualized segments optimized for performance and security. Advanced fault tolerance at the container and instance levels enhances system reliability. The proposed architecture ensures high throughput, low latency, and secure orchestration for real-time anomaly detection in OT networks. Performance evaluations validate its efficiency in throughput, deployment, and learning accuracy, providing a robust foundation for future ICS automation and data-driven decision-making.

Delgado, Brian G. Rodiles [University of Texas at ↗

Security and Privacy Issues in New 5G and 6G Capabilities

Slides for opening INL hosted panel on Security and Privacy Issues in New 5G and 6G Capabilities in the Security and Privacy of Next-Generation Networks (FutureG) Workshop co-located with NDSS Symposium 2025, San Diego, CA.

5G Security↗

Electrokinetically Driven Rare Earth Element Separation by Coated Capillary Arrays

I, Kyle McCarthy, am traveling to Austin, TX for the TechConnect World Innovation conference. At the conference, I will give an poster presentation on research findings from Energy and Homeland Security LDRD "A New, Green Approach to Rare Earth Element (REE) Purification Based on Electrokinetics." titled "Electrokinetically Driven Rare Earth Element Separation..." I will also attend other live presentations and conduct professional networking. This fits within Sandia's energy security mission.

Merrill, Laura Christine [Sandia National Laborato↗

Electrokinetic Rare Earth Element Purification

I, Kyle McCarthy, am traveling to Boston, MA for the Materials Research Society conference. At the conference, I will give an oral presentation on research findings from Energy and Homeland Security LDRD "A New, Green Approach to Rare Earth Element (REE) Purification Based on Electrokinetics." in talk titled "Electrokinetic Rare Earth Element Purification." I will also attend other live presentations and conduct professional networking. This fits within Sandia's energy security mission.

McCarthy, Kyle Patrick [Sandia National Laboratori↗

Encryption for Remote Control via Internet or Intranet

A data-communication protocol has been devised to enable secure, reliable remote control of processes and equipment via a collision-based network, while using minimal bandwidth and computation. The network could be the Internet or an intranet. Control is made secure by use of both a password and a dynamic key, which is sent transparently to a remote user by the controlled computer (that is, the computer, located at the site of the equipment or process to be controlled, that exerts direct control over the process). The protocol functions in the presence of network latency, overcomes errors caused by missed dynamic keys, and defeats attempts by unauthorized remote users to gain control. The protocol is not suitable for real-time control, but is well suited for applications in which control latencies up to about 0.5 second are acceptable. The encryption scheme involves the use of both a dynamic and a private key, without any additional overhead that would degrade performance. The dynamic key is embedded in the equipment- or process-monitor data packets sent out by the controlled computer: in other words, the dynamic key is a subset of the data in each such data packet. The controlled computer maintains a history of the last 3 to 5 data packets for use in decrypting incoming control commands. In addition, the controlled computer records a private key (password) that is given to the remote computer. The encrypted incoming command is permuted by both the dynamic and private key. A person who records the command data in a given packet for hostile purposes cannot use that packet after the public key expires (typically within 3 seconds). Even a person in possession of an unauthorized copy of the command/remote-display software cannot use that software in the absence of the password. The use of a dynamic key embedded in the outgoing data makes the central-processing unit overhead very small. The use of a National Instruments DataSocket(TradeMark) (or equivalent) protocol or the User Datagram Protocol makes it possible to obtain reasonably short response times: Typical response times in event-driven control, using packets sized .300 bytes, are <0.2 second for commands issued from locations anywhere on Earth. The protocol requires that control commands represent absolute values of controlled parameters (e.g., a specified temperature), as distinguished from changes in values of controlled parameters (e.g., a specified increment of temperature). Each command is issued three or more times to ensure delivery in crowded networks. The use of absolute-value commands prevents additional (redundant) commands from causing trouble. Because a remote controlling computer receives "talkback" in the form of data packets from the controlled computer, typically within a time interval < or =1 s, the controlling computer can re-issue a command if network failure has occurred. The controlled computer, the process or equipment that it controls, and any human operator(s) at the site of the controlled equipment or process should be equipped with safety measures to prevent damage to equipment or injury to humans. These features could be a combination of software, external hardware, and intervention by the human operator(s). The protocol is not fail-safe, but by adopting these safety measures as part of the protocol, one makes the protocol a robust means of controlling remote processes and equipment by use of typical office computers via intranets and/or the Internet.

Lineberger, Lewis↗

Recognition of partially occluded threat objects using the annealed Hopefield network

Recognition of partially occluded objects has been an important issue to airport security because occlusion causes significant problems in identifying and locating objects during baggage inspection. The neural network approach is suitable for the problems in the sense that the inherent parallelism of neural networks pursues many hypotheses in parallel resulting in high computation rates. Moreover, they provide a greater degree of robustness or fault tolerance than conventional computers. The annealed Hopfield network which is derived from the mean field annealing (MFA) has been developed to find global solutions of a nonlinear system. In the study, it has been proven that the system temperature of MFA is equivalent to the gain of the sigmoid function of a Hopfield network. In our early work, we developed the hybrid Hopfield network (HHN) for fast and reliable matching. However, HHN doesn't guarantee global solutions and yields false matching under heavily occluded conditions because HHN is dependent on initial states by its nature. In this paper, we present the annealed Hopfield network (AHN) for occluded object matching problems. In AHN, the mean field theory is applied to the hybird Hopfield network in order to improve computational complexity of the annealed Hopfield network and provide reliable matching under heavily occluded conditions. AHN is slower than HHN. However, AHN provides near global solutions without initial restrictions and provides less false matching than HHN. In conclusion, a new algorithm based upon a neural network approach was developed to demonstrate the feasibility of the automated inspection of threat objects from x-ray images. The robustness of the algorithm is proved by identifying occluded target objects with large tolerance of their features.

Kim, Jung H.↗