Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “encryption”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 217 records · Page 12

Towards Efficient Scientific Data Management Using Cloud Storage

A software prototype allows users to backup and restore data to/from both public and private cloud storage such as Amazon's S3 and NASA's Nebula. Unlike other off-the-shelf tools, this software ensures user data security in the cloud (through encryption), and minimizes users operating costs by using space- and bandwidth-efficient compression and incremental backup. Parallel data processing utilities have also been developed by using massively scalable cloud computing in conjunction with cloud storage. One of the innovations in this software is using modified open source components to work with a private cloud like NASA Nebula. Another innovation is porting the complex backup to- cloud software to embedded Linux, running on the home networking devices, in order to benefit more users.

He, Qiming↗

Autonomous Byte Stream Randomizer

Net-centric networking environments are often faced with limited resources and must utilize bandwidth as efficiently as possible. In networking environments that span wide areas, the data transmission has to be efficient without any redundant or exuberant metadata. The Autonomous Byte Stream Randomizer software provides an extra level of security on top of existing data encryption methods. Randomizing the data s byte stream adds an extra layer to existing data protection methods, thus making it harder for an attacker to decrypt protected data. Based on a generated crypto-graphically secure random seed, a random sequence of numbers is used to intelligently and efficiently swap the organization of bytes in data using the unbiased and memory-efficient in-place Fisher-Yates shuffle method. Swapping bytes and reorganizing the crucial structure of the byte data renders the data file unreadable and leaves the data in a deconstructed state. This deconstruction adds an extra level of security requiring the byte stream to be reconstructed with the random seed in order to be readable. Once the data byte stream has been randomized, the software enables the data to be distributed to N nodes in an environment. Each piece of the data in randomized and distributed form is a separate entity unreadable on its own right, but when combined with all N pieces, is able to be reconstructed back to one. Reconstruction requires possession of the key used for randomizing the bytes, leading to the generation of the same cryptographically secure random sequence of numbers used to randomize the data. This software is a cornerstone capability possessing the ability to generate the same cryptographically secure sequence on different machines and time intervals, thus allowing this software to be used more heavily in net-centric environments where data transfer bandwidth is limited.

Paloulian, George K.↗

Access Control of Web- and Java-Based Applications

Cybersecurity has become a great concern as threats of service interruption, unauthorized access, stealing and altering of information, and spreading of viruses have become more prevalent and serious. Application layer access control of applications is a critical component in the overall security solution that also includes encryption, firewalls, virtual private networks, antivirus, and intrusion detection. An access control solution, based on an open-source access manager augmented with custom software components, was developed to provide protection to both Web-based and Javabased client and server applications. The DISA Security Service (DISA-SS) provides common access control capabilities for AMMOS software applications through a set of application programming interfaces (APIs) and network- accessible security services for authentication, single sign-on, authorization checking, and authorization policy management. The OpenAM access management technology designed for Web applications can be extended to meet the needs of Java thick clients and stand alone servers that are commonly used in the JPL AMMOS environment. The DISA-SS reusable components have greatly reduced the effort for each AMMOS subsystem to develop its own access control strategy. The novelty of this work is that it leverages an open-source access management product that was designed for Webbased applications to provide access control for Java thick clients and Java standalone servers. Thick clients and standalone servers are still commonly used in businesses and government, especially for applications that require rich graphical user interfaces and high-performance visualization that cannot be met by thin clients running on Web browsers

Tso, Kam S.↗

Secure Naming and Addressing Operations for Store, Carry and Forward Networks

This paper describes concepts for secure naming and addressing directed at Store, Carry and Forward (SCF) distributed applications, where disconnection and intermittent connectivity between forwarding systems is the norm. The paper provides a brief overview of store, carry and forward distributed applications followed by an in depth discussion of how to securely: create a namespace; allocate names within the namespace; query for names known within a local processing system or connected subnetwork; validate ownership of a given name; authenticate data from a given name; and, encrypt data to a given name. Critical issues such as revocation of names, mobility and the ability to use various namespaces to secure operations or for Quality-of-Service are also presented. Although the concepts presented for naming and addressing have been developed for SCF, they are directly applicable to fully connected systems.

computer security↗

Access Control of Web and Java Based Applications

Cyber security has gained national and international attention as a result of near continuous headlines from financial institutions, retail stores, government offices and universities reporting compromised systems and stolen data. Concerns continue to rise as threats of service interruption, and spreading of viruses become ever more prevalent and serious. Controlling access to application layer resources is a critical component in a layered security solution that includes encryption, firewalls, virtual private networks, antivirus, and intrusion detection. In this paper we discuss the development of an application-level access control solution, based on an open-source access manager augmented with custom software components, to provide protection to both Web-based and Java-based client and server applications.

cybersecurity↗

Tactically Extensible and Modular Communications - X-Band TEMCOM-X

This paper will discuss a proposed CubeSat size (3U) telemetry system concept being developed at Marshall Space Flight Center (MSFC) in cooperation with the U.S. Department of the Army and Dynetics Corporation. This telemetry system incorporates efficient, high-bandwidth communications by developing flight-ready, low-cost, Protoflight software defined radio (SDR) and Electronically Steerable Patch Array (ESPA) antenna subsystems for use on platforms as small as CubeSats and unmanned aircraft systems (UASs). The current telemetry system is slightly larger in dimension of footprint than required to fit within a 0.5U CubeSat volume. Extensible and modular communications for CubeSat technologies will partially mitigate current capability gaps between traditional strategic space platforms and lower-cost small satellite solutions. Higher bandwidth capacity will enable high-volume, low error-rate data transfer to and from tactical forces or sensors operating in austere locations (e.g., direct imagery download, unattended ground sensor data exfiltration, interlink communications), while also providing additional bandwidth and error correction margin to accommodate more complex encryption algorithms and higher user volume.

Sims, William Herbert↗

High Data Rates for AubieSat-2 A & B, Two CubeSats Performing High Energy Science in the Upper Atmosphere

This paper will discuss a proposed CubeSat size (3 Units / 6 Units) telemetry system concept being developed at Marshall Space Flight Center (MSFC) in cooperation with Auburn University. The telemetry system incorporates efficient, high-bandwidth communications by developing flight-ready, low-cost, PROTOFLIGHT software defined radio (SDR) payload for use on CubeSats. The current telemetry system is slightly larger in dimension of footprint than required to fit within a 0.75 Unit CubeSat volume. Extensible and modular communications for CubeSat technologies will provide high data rates for science experiments performed by two CubeSats flying in formation in Low Earth Orbit. The project is a collaboration between the University of Alabama in Huntsville and Auburn University to study high energy phenomena in the upper atmosphere. Higher bandwidth capacity will enable high-volume, low error-rate data transfer to and from the CubeSats, while also providing additional bandwidth and error correction margin to accommodate more complex encryption algorithms and higher user volume.

Sims, William H.↗

Enabling a Science Support Structure for NASAs Global Hawk UASs

In this paper we describe the information technologies developed by NASA for the Winter/Spring 2013/2014, and Fall 2014, NASA Earth Venture Campaigns, Hurricane and Severe Storm Sentinel (HS3) and Airborne Tropical TRopopause EXperiment (ATTREX). These campaigns utilized Global Hawk UAS vehicles equipped at the NASA Armstrong (previously Dryden) Flight Research Facility (AFRC), Edwards Air Force Base, California, and operated from there, the NASA Wallops Flight Facility (WFF), Virginia, and Anderson Air Force Base (AAFB), Guam. Part of this enabling infrastructure utilized a layer 2 encrypted terrestrial Virtual Local Area Network (VLAN) that, at times, spanned greater than ten thousand miles (AAFB <-> AFRC <-> WFF) and was routed over geosynchronous Ku band communication Satellites directly to the aircraft sensor network. This infrastructure enabled seamless hand off between Satellites, and Satellite ground stations in Guam, California and Virginia, so allowing simultaneous Aircraft Command and Control and Science operations from remote locations. Additionally, we will describe the other elements of this infrastructure, from on-board geo-enabled databases, to real time communications directly from the instruments (in some cases, more than twelve were carried, and simultaneously operated, on one aircraft) to the researchers and other interested parties, world wide.

Virtual Local Area Network (VLAN)↗

Cyber Safety and Security for Reduced Crew Operations (RCO)

NASA and the Aviation Industry is looking into reduced crew operations (RCO) that would cut today's required two-person flight crews down to a single pilot with support from ground-based crews. Shared responsibility across air and ground personnel will require highly reliable and secure data communication and supporting automation, which will be safety-critical for passenger and cargo aircraft. This paper looks at the different types and degrees of authority delegation given from the air to the ground and the ramifications of each, including the safety and security hazards introduced, the mitigation mechanisms for these hazards, and other demands on an RCO system architecture which would be highly invasive into (almost) all safety-critical avionics. The adjacent fields of unmanned aerial systems and autonomous ground vehicles are viewed to find problems that RCO may face and related aviation accident scenarios are described. The paper explores possible data communication architectures to meet stringent performance and information security (INFOSEC) requirements of RCO. Subsequently, potential challenges for RCO data communication authentication, encryption and non-repudiation are identified.

Communications↗

Cyber Safety and Security for Reduced Crew Operations (RCO)

NASA and the Aviation Industry is looking into reduced crew operations (RCO) that would cut today's required two-person flight crews down to a single pilot with support from ground-based crews. Shared responsibility across air and ground personnel will require highly reliable and secure data communication and supporting automation, which will be safety-critical for passenger and cargo aircraft. This paper looks at the different types and degrees of authority delegation given from the air to the ground and the ramifications of each, including the safety and security hazards introduced, the mitigation mechanisms for these hazards, and other demands on an RCO system architecture which would be highly invasive into (almost) all safety-critical avionics. The adjacent fields of unmanned aerial systems and autonomous ground vehicles are viewed to find problems that RCO may face and related aviation accident scenarios are described. The paper explores possible data communication architectures to meet stringent performance and information security (INFOSEC) requirements of RCO. Subsequently, potential challenges for RCO data communication authentication, encryption and non-repudiation are identified. The approach includes a comprehensive safety-hazard analysis of the RCO system to determine top level INFOSEC requirements for RCO and proposes an option for effective RCO implementation. This paper concludes with questioning the economic viability of RCO in light of the expense of overcoming the operational safety and security hazards it would introduce.

Aircraft Communication↗

Blockchain Application Within a Multi-Sensor Satellite Architecture

With the thrust towards multi-sensor satellite architectures for earth and space exploration, such as constellations and swarms, new technologies are required to enable the transition to this future capability. One of the areas of interest is establishing secure, efficient and prioritized data and command communication pathways among ground and space-based sources for such systems. This paper presents early research results on the potential role, capabilities and value of blockchain usage within constellation and swarm satellite architectures. It demonstrates the use of blockchain's smart contract and distributed ledger capabilities for secure and prioritized multi-sensor satellite collaborative data exchanges, as well as the logging and tracking of command and control events. Adapting and utilizing this emerging technology will aid in addressing technology gaps expected from future constellation flight architectures, such as managing collective computational operations (correlation), dynamic and autonomous observation planning, time-critical events, and provenance tied to ground and space-based autonomous operations and control recordkeeping. In this scenario blockchain is applied in encrypted command transmittal to multiple, yet specific, entities enabling acknowledgement transmittals, performance scalability, and automatic event-based triggering.

Mital, Rohit↗

Medical Data Architecture (MDA) Project Status

The Medical Data Architecture (MDA) project supports the Exploration Medical Capability (ExMC) risk to minimize or reduce the risk of adverse health outcomes and decrements in performance due to in-flight medical capabilities on human exploration missions. To mitigate this risk, the ExMC MDA project addresses the technical limitations identified in ExMC Gap Med 07: We do not have the capability to comprehensively process medically-relevant information to support medical operations during exploration missions. This gap identifies that the current in-flight medical data management includes a combination of data collection and distribution methods that are minimally integrated with on-board medical devices and systems. Furthermore, there are a variety of data sources and methods of data collection. For an exploration mission, the seamless management of such data will enable a more medically autonomous crew than the current paradigm. The medical system requirements are being developed in parallel with the exploration mission architecture and vehicle design. ExMC has recognized that in order to make informed decisions about a medical data architecture framework, current methods for medical data management must not only be understood, but an architecture must also be identified that provides the crew with actionable insight to medical conditions. This medical data architecture will provide the necessary functionality to address the challenges of executing a self-contained medical system that approaches crew health care delivery without assistance from ground support. Hence, the products supported by current prototype development will directly inform exploration medical system requirements.In fiscal year 2018, the MDA project developed Test Bed 2, the second iteration in a series of prototypes with functionality focused on data security through role-based access control and encryption, integration with One Portal exercise software and ingestion of an ultrasound Digital Imaging and Communications in Medicine (DICOM) file and image display. Test Bed 2 advances the medical data system architecture framework by providing these functionalities in a scalable system that maintained a layered, modular design. The architecture framework uses a data services approach with role-based access to data in a customized medical record system suitable for space exploration. These functionalities were demonstrated as part of the Next Space Technologies for Exploration Partnerships (NextSTEP) ground test demonstrated at the NASA Johnson Space Center Integrated Power, Avionics and Software (iPAS) facility. Interfacing to a Core Flight Software (CFS) system, the MDA system, using Consultative Committee for Space Data Systems (CCSDS) protocol, transferred an exercise file from the simulated flight MDA system to a mirrored MDA system on the ground through the CFS system. The selection of data sources and demonstrations enabled the team to address stakeholder concerns throughout the development process. In the next iteration, the MDA team will work with stakeholders to identify additional relevant functionalities to further advance system data models, standards and principles that will inform the medical system requirements development.

medical data architecture↗

Bit Error Rate and Frame Error Rate Data Processing for Space Communications and Navigation-Related Communication System Analysis Tools

One of the capabilities that the Space Communications and Navigation (SCaN) Strategic Center for Networking, Integration, and Communications (SCENIC) user interface (UI) web application intends to provide its users is the addition of network protocol and link encryption augmentations of communication system analyses. Before any of these analyses capabilities can be modeled, the simulations of bit error rate (BER) and frame error rate (FER) against signal-to-noise ratio (SNR) have been conducted, requiring parameters from several known coding types (low-density parity-check (LDPC), convolutional, etc.), signal modulations (binary phase shift keying (BPSK), quadrature phase shift keying (QPSK), etc.), coding rates (1/2, 1/3, etc.), and frame sizes (1,280, 3,580, etc.). However, in order to extract useful information from the results of these simulations, a curve fitting technique has been applied to each resulting dataset to extend and extrapolate the curve fit of BER and FER down to 10–30 using MATLAB® Curve Fitting Toolbox™ (The MathWorks, Inc.). This is a necessary step because simulations of BER and FER were only performed to around 10–9 due to the extensive simulation time that would be required to obtain significant simulation results at the error levels desired. Furthermore, the fitted curve results were applied to a finer resolution for the SNR at 0.01-dB interval instead of the 0.05-dB interval limitation used in the simulation. All the possible combinations of the coding types, signal modulations, coding rates, frame sizes, and the extension of BER and FER curves would enable users to capture a wide range of link performances that directly relates to the addition of higher level networking data encapsulated in a frame. The curve fitting results also led to the modeling of the optical link error rate performance by solving for coding gain, FER_BER SNR delta, coded optical BER-SNR, and coded optical FER–SNR.

Communication link analysis↗

Quantum Technologies for UAS (QTech)

Recent advances in small Unmanned Aerial System (sUAS) technologies lower the barriers for use by both private and commercial entities. However, these advances are also likely to lead to greater vehicle densities, a more heterogenous mix of vehicles and equipment and greater levels of vehicle autonomy, which can increase the chance for communications disruptions. For the safe and secure operation of these vehicles, it is essential to have a robust communications network. This work is focused on harnessing the power of quantum technologies to enable this robust communications network by: (1) utilizing quantum optimization algorithms to design robust network with routing redundancy that can respond adaptively to dynamically changing real-time environment and disruptions, (2) utilize quantum optimization algorithms resource allocation for detection, localization, and tracking of mobile communication disruption agents and (3) utilize quantum key distribution (QKD) to execute secure key sharing in anti-jamming protocols for secure radio frequency (RF) communication. Efforts to map these quantum optimization algorithms to commercially available quantum annealers and soon to be available general-purpose gate-model quantum hardware architectures will be reviewed, and plans for testing the solutions to these algorithms through indoor sUAS flight tests will be discussed. Lastly, efforts to miniaturize and practically deploy Quantum Key Distribution (QKD) hardware, which could ultimately be used to securely exchange encryption keys, in sUAS networks will be reviewed.

Quantum Computing↗

DSN Wide Area Network Architecture, Capacity and Performance

This paper discusses the architecture of the wide area network that connects key communications facilities within the National Aeronautic and Space Administration (NASA) Deep Space Network (DSN). Several considerations are given to the design of this wide area network to ensure a timely, reliable, and secure data delivery between the mission users and their spacecraft. The network star configuration simplifies data delivery to users and minimizes operational cost. The dual-path connections maximize the system reliability, with geographical diversity in data routing to avoid single point of failure. Data encryption enhances the protection of mission users’ data. The system bandwidth is determined by balancing the needs to minimize the operating bandwidth cost and to have sufficient bandwidth to be able to deliver data to all users within the required. The DSN uses a class base weighted fair queuing (CBWFQ) method in its data delivery. This scheme guarantees a minimum bandwidth to each class of users and allows users to also access any unused bandwidth by other groups. The paper will also show performance of system reliability and bandwidth margin.

Liao, Jason↗

Simulation and Modeling Concepts for Secure Airspace Operations

With the expected advent of new entrants including Unmanned Aerial Systems, Commercial Launch Vehicles and Urban Air Mobility aircraft, the future United States National Airspace System will have to evolve to include their operations along with the current commercial, general aviation and military operations. The National Aeronautics and Space Administration and the Federal Aviation Administration are working together to provide a vision for aviation operations in the future—2045 and beyond. Their National Airspace System Horizons initiative seeks to provide stakeholders a list of operational scenarios and technologies, concepts and strategies needed for supporting that vision. They have identified cybersecurity as one of the seven strategic interest areas for realizing this vision. Consequently, NASA is studying cyber resiliency for secure airspace operations. This paper examines cyber security vulnerabilities of Urban Air Mobility operations. While there are many pathways to attack a cyber physical system such as Urban Air Mobility, their effect is expressed in modification or corruption of data/information used for controlling vehicles and making operational decisions. The paper describes cybersecurity technologies of Encryption, Blockchain, Virtual Information Fabric Infrastructure, Trusted Platform Module and Anomaly Detection for protecting the data, thus, improving the cyber resiliency of the current and future air traffic management system.

Cybersecurity↗

Simulation and Modeling Concepts for Secure Airspace Operations

This paper examines cyber security vulnerabilities of Urban Air Mobility operations. With the expected advent of new entrants including Unmanned Aerial Systems, Commercial Launch Vehicles and Urban Air Mobility aircraft, the future United States National Airspace System will have to evolve to include their operations along with the current commercial, general aviation and military operations. The National Aeronautics and Space Administration and the Federal Aviation Administration are working together to provide a vision for aviation operations in the future—2045 and beyond. Their National Airspace System Horizons initiative seeks to provide stakeholders a list of operational scenarios and technologies, concepts and strategies needed for supporting that vision. They have identified cybersecurity as one of the seven strategic interest areas for realizing this vision. Consequently, NASA is studying cyber resiliency for secure airspace operations. While there are many pathways to attack a cyber physical system such as Urban Air Mobility, their effect is expressed in modification or corruption of data/information used for controlling vehicles and making operational decisions. The paper describes cybersecurity technologies of Encryption, Blockchain, Virtual Information Fabric Infrastructure, Trusted Platform Module and Anomaly Detection for protecting the data, and the cyber resiliency of the current and future air traffic management system.

Urban Air Mobility↗

Simulation and Modeling Concepts for Secure Airspace Operations

This paper examines cyber security vulnerabilities of Urban Air Mobility operations. With the expected advent of new entrants including Unmanned Aerial Systems, Commercial Launch Vehicles and Urban Air Mobility aircraft, the future United States National Airspace System will have to evolve to include their operations along with the current commercial, general aviation and military operations. The National Aeronautics and Space Administration and the Federal Aviation Administration are working together to provide a vision for aviation operations in the future—2045 and beyond. Their National Airspace System Horizons initiative seeks to provide stakeholders a list of operational scenarios and technologies, concepts and strategies needed for supporting that vision. They have identified cybersecurity as one of the seven strategic interest areas for realizing this vision. Consequently, NASA is studying cyber resiliency for secure airspace operations. While there are many pathways to attack a cyber physical system such as Urban Air Mobility, their effect is expressed in modification or corruption of data/information used for controlling vehicles and making operational decisions. The paper describes cybersecurity technologies of Encryption, Blockchain, Virtual Information Fabric Infrastructure, Trusted Platform Module and Anomaly Detection for protecting the data, and the cyber resiliency of the current and future air traffic management system.

Urban Air Mobility↗