Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Network Security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 235 records · Page 13

Encrypted Control Using Modified Learning With Errors-based Schemes

Cyber-physical systems (CPSs) require reliable, safe, and secure control of critical infrastructure, combining computational and networking capabilities, which heighten the risk of cyber attacks. These attacks can disrupt the physical process, causing unforeseen consequences. One solution is the use of fully homomorphic encryption (FHE) to protect the control loop, allowing for secure computations and communications without compromising signal and control system privacy. The challenge with FHE, however, is its requirement for inputs to be integers. This paper introduces a modified Learning With Errors (LWE) FHE approach that encodes control system dynamics and signals into integers. Our proposed scheme leverages a generalized LWE encoding function and modifies the Gentry-Sahai-Waters (GSW) gadget decomposition tool to encrypt the control system. Using the modified LWE scheme, we formalize a fully encrypted control system, supported by simulated results.

42 - ENGINEERING↗

Experiments for Securing Air Traffic Against Cyber-Physical System Attacks

This presentation describes experiments conducted with single board computers to investigate methods for creating trust for enabling the development of cyber-resilient air transportation systems. Methods included secure communication to prevent unauthorized access to data, consistency of data obtained via sensors and by processing, and built-in safeguards to prevent mission failure. The motivation for this work are the following. The future air transportation system needs to ensure availability, integrity, confidentiality and safety of operations. Safety of vehicles and operations is paramount for successful integration of Urban Air Mobility (UAM), Unmanned Aerial Systems (UAS), supersonic aircraft and launch vehicles with conventional aviation operations in the National Airspace System. Security is becoming critical because the sensors, networks and computers are far more vulnerable to bad actors than their mechanical or human predecessors. The goal therefore is to design and develop cyber-resilient systems that continue to function even in degraded states. The main findings are (1) off-the-shelf hardware can support development of cyber-resilient onboard flight computers and (2) trust in system design and implementation can be accomplished by integrating layers in depth (detail) and in breadth (scope).

cyber-resilient autonomy, trust, secure communicat↗

PLC Vulnerabilities and Mitigations

Programmable Logic Controllers (PLCs) are used extensively in many high-importance industrial and nonindustrial settings including controlling elevators, manufacturing machines, and utility facilities such as power and natural gas, however cybersecurity protection for them has been neglected. Within recent years, PLCs have been put under more security scrutiny and experts have advocated for changes from the addition of protocol encryption and network segmentation to intrusion detection systems on the PLCs themselves. While PLC security is critical, a large portion of the PLCs available today will never receive these changes due to being legacy or the difficulty of overhauling the security on existing systems. Due to the infeasibility of applying many recommended security measures towards currently available machines, we aim to provide realistic and affordable best practices for hardening PLCs. We will first conduct security analysis and consider attack vectors within our target PLC. Once we’ve analyzed the device’s security, we will evaluate a variety of mitigation methods and create guidelines to effectively reduce the threat posed by PLC attacks with minimal disruption to operations.

42 ENGINEERING↗

UNIX security in a supercomputing environment

The author critiques some security mechanisms in most versions of the Unix operating system and suggests more effective tools that either have working prototypes or have been implemented, for example in secure Unix systems. Although no computer (not even a secure one) is impenetrable, breaking into systems with these alternate mechanisms will cost more, require more skill, and be more easily detected than penetrations of systems without these mechanisms. The mechanisms described fall into four classes (with considerable overlap). User authentication at the local host affirms the identity of the person using the computer. The principle of least privilege dictates that properly authenticated users should have rights precisely sufficient to perform their tasks, and system administration functions should be compartmentalized; to this end, access control lists or capabilities should either replace or augment the default Unix protection system, and mandatory access controls implementing multilevel security models and integrity mechanisms should be available. Since most users access supercomputing environments using networks, the third class of mechanisms augments authentication (where feasible). As no security is perfect, the fourth class of mechanism logs events that may indicate possible security violations; this will allow the reconstruction of a successful penetration (if discovered), or possibly the detection of an attempted penetration.

Bishop, Matt↗

Space Communications and Navigation (SCaN) Integrated Network Architecture Definition Document (ADD): Executive Summary - Volume 1

The SCaN Program has defined an integrated network architecture that fully meets the Administrator s mandate to the Program, and will result in a NASA infrastructure capable of providing the needed and enabling communications services to future space missions. The integrated network architecture will increase SCaN operational efficiency and interoperability through standardization, commonality and technology infusion. It will enable NASA missions requiring advanced communication and tracking capabilities such as: a. Optical communication b. Antenna arraying c. Lunar and Mars Relays d. Integrated network management (service management and network control) and integrated service execution e. Enhanced tracking for navigation f. Space internetworking with DTN and IP g. End-to-end security h. Enhanced security services Moreover, the SCaN Program has created an Integrated Network Roadmap that depicts an orchestrated and coherent evolution path toward the target architecture, encompassing all aspects that concern network assets (i.e., operations and maintenance, sustaining engineering, upgrade efforts, and major development). This roadmap identifies major NASA ADPs, and shows dependencies and drivers among the various planned undertakings and timelines. The roadmap is scalable to accommodate timely adjustments in response to Agency needs, goals, objectives and funding. Future challenges to implementing this architecture include balancing user mission needs, technology development, and the availability of funding within NASA s priorities. Strategies for addressing these challenges are to: define a flexible architecture, update the architecture periodically, use ADPs to evaluate options and determine when to make decisions, and to engage the stakeholders in these evaluations. In addition, the SCaN Program will evaluate and respond to mission need dates for technical and operational capabilities to be provided by the SCaN integrated network. In that regard, the architecture defined in this ADD is scalable to accommodate programmatic and technical changes.

Younes, Badri A.↗

Food Security, Decision Making and the Use of Remote Sensing in Famine Early Warning Systems

Famine early warning systems use remote sensing in combination with socio-economic and household food economy analysis to provide timely and rigorous information on emerging food security crises. The Famine Early Warning Systems Network (FEWS NET) is the US Agency for International Development's decision support system in 20 African countries, as well as in Guatemala, Haiti and Afghanistan. FEWS NET provides early and actionable policy guidance for the US Government and its humanitarian aid partners. As we move into an era of climate change where weather hazards will become more frequent and severe, understanding how to provide quantitative and actionable scientific information for policy makers using biophysical data is critical for an appropriate and effective response.

Brown, Molly E.↗

Lunar Utilization Control Area (LUCA): Configurable Mission Control Rooms and the Benefits to Future Spaceflight

Configurable Control Rooms provide the ability to rapidly change capabilities from mission to mission and customer to customer. Future missions will likely not have the 24/7/365 need for a dedicated mission support room, and CCR could easily be adapted for continuous support if needed. CCRs offer physical, centralized locations for teams to support, and the HOSC provides a secure, reliable facility with constant monitoring by network specialists. Institutions and payload teams can cost save by utilizing a CCR at MSFC eliminating the need to assemble an entire custom control room at their location. This new paradigm in flight operations can ease the creation of any mission from a cubesat to a New Frontiers or Flagship program and anything in between.

Configurable Control Rooms↗

Quantum Technologies for UAS (QTech)

Recent advances in small Unmanned Aerial System (sUAS) technologies lower the barriers for use by both private and commercial entities. However, these advances are also likely to lead to greater vehicle densities, a more heterogenous mix of vehicles and equipment and greater levels of vehicle autonomy, which can increase the chance for communications disruptions. For the safe and secure operation of these vehicles, it is essential to have a robust communications network. This work is focused on harnessing the power of quantum technologies to enable this robust communications network by: (1) utilizing quantum optimization algorithms to design robust network with routing redundancy that can respond adaptively to dynamically changing real-time environment and disruptions, (2) utilize quantum optimization algorithms resource allocation for detection, localization, and tracking of mobile communication disruption agents and (3) utilize quantum key distribution (QKD) to execute secure key sharing in anti-jamming protocols for secure radio frequency (RF) communication. Efforts to map these quantum optimization algorithms to commercially available quantum annealers and soon to be available general-purpose gate-model quantum hardware architectures will be reviewed, and plans for testing the solutions to these algorithms through indoor sUAS flight tests will be discussed. Lastly, efforts to miniaturize and practically deploy Quantum Key Distribution (QKD) hardware, which could ultimately be used to securely exchange encryption keys, in sUAS networks will be reviewed.

Quantum Computing↗

Criteria for Evaluating Alternative Network and Link Layer Protocols for the NASA Constellation Program Communication Architecture

Selecting a communications and network architecture for future manned space flight requires an evaluation of the varying goals and objectives of the program, development of communications and network architecture evaluation criteria, and assessment of critical architecture trades. This paper uses Cx Program proposed exploration activities as a guideline; lunar sortie, outpost, Mars, and flexible path options are described. A set of proposed communications network architecture criteria are proposed and described. They include: interoperability, security, reliability, and ease of automating topology changes. Finally a key set of architecture options are traded including (1) multiplexing data at a common network layer vs. at the data link layer, (2) implementing multiple network layers vs. a single network layer, and (3) the use of a particular network layer protocol, primarily IPv6 vs. Delay Tolerant Networking (DTN). In summary, the protocol options are evaluated against the proposed exploration activities and their relative performance with respect to the criteria are assessed. An architectural approach which includes (a) the capability of multiplexing at both the network layer and the data link layer and (b) a single network layer for operations at each program phase, as these solutions are best suited to respond to the widest array of program needs and meet each of the evaluation criteria.

Benbenek, Daniel↗

The Urban Deployment Model: A Toolset for the Simulation and Performance Characterization of Radiation Detector Deployments in Urban Environments

Static and mobile radiation detectors can be deployed in urban environments for a range of nuclear security applications, including radiological source search-and-tracking scenarios. Modeling detector performance for such applications is challenging, as it does not depend solely on the detector capabilities themselves. Many factors must be taken into consideration, including specific source and background signatures, the topology and constraints of the deployment environment, the presence of nuisance sources, and whether detectors are mobile or static. When considering the simultaneous deployment of multiple, heterogeneous detectors, assessment of the system-wide performance requires the simulation of the individual detectors, and a system-level analysis of the detection performance. In radiological source search-and-tracking scenarios, performance is mostly dominated by the probability of encounter, which depends on the specifics of a given deployment, e.g., static vs. mobile detectors or a combination of both modalities, the number of detectors deployed, the dynamic vs. static setting of false alarm rates, and individual vs. networked operation. The Urban Deployment Model (UDM) toolset was specifically developed to cover the gap in the available generic frameworks for the simulation of radiation detector deployments at city scales. UDM provides a unified and modular framework to support the simulation and performance characterization of heterogeneous detector deployments in urban environments. This paper presents the key components along the UDM workflow.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

The Design and Evaluation of Zero Trust Architecture for Electric Vehicle Charging Infrastructure: EVs @ Scale Series on EV Charging Station Cybersecurity

Implementing a zero trust architecture can significantly bolster the security of electric vehicle (EV) charging infrastructure. EV charging infrastructure includes numerous networked interfaces, each of which can present potential vulnerabilities. When these vulnerabilities are exploited, they can compromise the entire system, leading to severe operational and security risks. Zero trust is a security model that operates on the principle of "never trust, always verify," which helps manage the attack surface and limit the scope of any potential compromises. Fundamentally, this model ensures that no entity, whether inside or outside the network, is trusted by default. The design principles of zero trust include continuous verification, strict deny-by-default access controls, and micro-segmentation. Continuous verification ensures that every request is thoroughly checked, regardless of its origin. Strict access controls enforce the principle of least privilege, allowing users and devices only the minimum necessary access to perform their functions. Micro-segmentation involves dividing the network into smaller, isolated segments to prevent lateral movement in case of a breach. In the context of EV charging infrastructure, zero trust can be implemented through various strategies. For example, multi-factor authentication (MFA) can be required for engineers to access the management interfaces and control systems of charging stations. Real-time monitoring and analysis of network traffic can help detect and respond to anomalies. Systems that do not need to communicate with each other can be micro-segmented to enhance security. All communications should adhere to predefined policies to be permitted. Additionally, encrypting communications can protect sensitive information exchanged between chargers and management systems. This paper presents a zero trust architecture specifically designed for EV charging infrastructure. Implementing zero trust not only mitigates risks but also builds a resilient infrastructure capable of withstanding and quickly recovering from cyber threats. The architecture addresses six defined security objectives. A comprehensive test plan is developed to assess the architecture against these objectives, and the results of the evaluation are reported. This approach is essential for maintaining the reliability and integrity of EV charging services in an increasingly interconnected and vulnerable digital landscape. This is the first in a planned series of papers exploring the implementation of zero trust in EV charging infrastructure. Each paper will delve into different aspects and applications of zero trust, highlighting how various work processes and requirements can lead to distinct architectural designs. These architectures will be tailored to address specific security challenges and operational needs within the EV charging ecosystem, ensuring a robust and adaptable security framework.

33 ADVANCED PROPULSION SYSTEMS↗

High End Computer Network Testbedding at NASA Goddard Space Flight Center

The Earth & Space Data Computing (ESDC) Division, at the Goddard Space Flight Center, is involved in development and demonstrating various high end computer networking capabilities. The ESDC has several high end super computers. These are used to run: (1) computer simulation of the climate systems; (2) to support the Earth and Space Sciences (ESS) project; (3) to support the Grand Challenge (GC) Science, which is aimed at understanding the turbulent convection and dynamos in stars. GC research occurs in many sites throughout the country, and this research is enabled by, in part, the multiple high performance network interconnections. The application drivers for High End Computer Networking use distributed supercomputing to support virtual reality applications, such as TerraVision, (i.e., three dimensional browser of remotely accessed data), and Cave Automatic Virtual Environments (CAVE). Workstations can access and display data from multiple CAVE's with video servers, which allows for group/project collaborations using a combination of video, data, voice and shared white boarding. The ESDC is also developing and demonstrating the high degree of interoperability between satellite and terrestrial-based networks. To this end, the ESDC is conducting research and evaluations of new computer networking protocols and related technologies which improve the interoperability of satellite and terrestrial networks. The ESDC is also involved in the Security Proof of Concept Keystone (SPOCK) program sponsored by National Security Agency (NSA). The SPOCK activity provides a forum for government users and security technology providers to share information on security requirements, emerging technologies and new product developments. Also, the ESDC is involved in the Trans-Pacific Digital Library Experiment, which aims to demonstrate and evaluate the use of high performance satellite communications and advanced data communications protocols to enable interactive digital library data access between the U. S. Library of Congress, the National Library of Japan and other digital library sites at 155 MegaBytes Per Second. The ESDC participation in this program is the Trans-Pacific access to GLOBE visualizations in real time. ESDC is participating in the Department of Defense's ATDNet with Multiwavelength Optical Network (MONET) a fully switched Wavelength Division Networking testbed. This presentation is in viewgraph format.

Gary, James Patrick↗

Virtualization - A Key Cost Saver in NASA Multi-Mission Ground System Architecture

With science team budgets being slashed, and a lack of adequate facilities for science payload teams to operate their instruments, there is a strong need for innovative new ground systems that are able to provide necessary levels of capability processing power, system availability and redundancy while maintaining a small footprint in terms of physical space, power utilization and cooling.The ground system architecture being presented is based off of heritage from several other projects currently in development or operations at Goddard, but was designed and built specifically to meet the needs of the Science and Planetary Operations Control Center (SPOCC) as a low-cost payload command, control, planning and analysis operations center. However, this SPOCC architecture was designed to be generic enough to be re-used partially or in whole by other labs and missions (since its inception that has already happened in several cases!)The SPOCC architecture leverages a highly available VMware-based virtualization cluster with shared SAS Direct-Attached Storage (DAS) to provide an extremely high-performing, low-power-utilization and small-footprint compute environment that provides Virtual Machine resources shared among the various tenant missions in the SPOCC. The storage is also expandable, allowing future missions to chain up to 7 additional 2U chassis of storage at an extremely competitive cost if they require additional archive or virtual machine storage space.The software architecture provides a fully-redundant GMSEC-based message bus architecture based on the ActiveMQ middleware to track all health and safety status within the SPOCC ground system. All virtual machines utilize the GMSEC system agents to report system host health over the GMSEC bus, and spacecraft payload health is monitored using the Hammers Integrated Test and Operations System (ITOS) Galaxy Telemetry and Command (TC) system, which performs near-real-time limit checking and data processing on the downlinked data stream and injects messages into the GMSEC bus that are monitored to automatically page the on-call operator or Systems Administrator (SA) when an off-nominal condition is detected. This architecture, like the LTSP thin clients, are shared across all tenant missions.Other required IT security controls are implemented at the ground system level, including physical access controls, logical system-level authentication authorization management, auditing and reporting, network management and a NIST 800-53 FISMA-Moderate IT Security plan Risk Assessment Contingency Plan, helping multiple missions share the cost of compliance with agency-mandated directives.The SPOCC architecture provides science payload control centers and backup mission operations centers with a cost-effective, standardized approach to virtualizing and monitoring resources that were traditionally multiple racks full of physical machines. The increased agility in deploying new virtual systems and thin client workstations can provide significant savings in personnel costs for maintaining the ground system. The cost savings in procurement, power, rack footprint and cooling as well as the shared multi-mission design greatly reduces upfront cost for missions moving into the facility. Overall, the authors hope that this architecture will become a model for how future NASA operations centers are constructed!

Ground System Architecture↗

The Space Superhighway: Space Infrastructure for the 21st Century

This paper introduces a concept for space infrastructure developed with input from multiple U.S. government agencies called the Space Superhighway, which could support civil, commercial, and national security space activities. The Space Superhighway is a commercial-first space infrastructure that contains three primary components: regional hubs, a sustainable transportation network, and Earth-to-orbit logistics. Civil, commercial, and national security space sectors could use this common infrastructure to support missions such as satellite servicing, Earth science, and space domain awareness, among others. It utilizes a commercial-first, “infrastructure-as-a-service” approach which contains industry-owned and operated assets with government anchor tenants for commercial services, enabling extended mission lifetime, on-orbit repair, maneuver without regret, and debris mitigation and removal. The Space Superhighway is the space infrastructure needed for the 21st century.

space superhighway↗

The Space Superhighway: Space Infrastructure for the 21st Century

This poster introduces a concept for space infrastructure developed with input from multiple U.S. government agencies called the Space Superhighway, which could support civil, commercial, and national security space activities. The Space Superhighway is a commercial-first space infrastructure that contains three primary components: regional hubs, a sustainable transportation network, and Earth-to-orbit logistics. Civil, commercial, and national security space sectors could use this common infrastructure to support missions such as satellite servicing, Earth science, and space domain awareness, among others. It utilizes a commercial-first, “infrastructure-as-a-service” approach which contains industry-owned and operated assets with government anchor tenants for commercial services, enabling extended mission lifetime, on-orbit repair, maneuver without regret, and debris mitigation and removal. The Space Superhighway is the space infrastructure needed for the 21st century.

space infrastructure↗

System security in the space flight operations center

The Space Flight Operations Center is a networked system of workstation-class computers that will provide ground support for NASA's next generation of deep-space missions. The author recounts the development of the SFOC system security policy and discusses the various management and technology issues involved. Particular attention is given to risk assessment, security plan development, security implications of design requirements, automatic safeguards, and procedural safeguards.

Wagner, David A.↗

Reconfigurable Network Slicing Orchestration in Network Function Virtualization Compatible Operational Technology Environment

The ongoing transition to Industry 4.0, which is characterized by increased inter-connectivity of cyber-physical systems, requires having time-sensitive, high throughput, and secure transfer of critical data in industrial sites. In this context, network slicing emerges as a critical tool to ensure timely data delivery by provisioning the network resources to cater to specific applications’ requirements and mitigating potential cyber attacks. To address these challenges, this paper aims to tackle two key questions essential for the successful implementation of network slicing in industrial environments. First, it investigates architectural considerations for developing a network infrastructure capable of supporting network slicing functionalities effectively. The proposed approach significantly improves deployment efficiency over traditional manual configurations. Second, it delves into the automated orchestration process, elucidating the steps and components involved in transitioning from a static network management approach to dynamically leverage network function virtualization schemes for creating network slices in ad-hoc manner. The system demonstrates high throughput suitable for production-level solutions and maintains exceptionally low latency, making it ideal for ultra-reliable low-latency communications. Even with increased network demands, the system remains stable, with effective Quality of Service (QoS) management, ensuring reliable performance under varying conditions. The proposed architecture outlines the necessary components, services, and communication protocols required for a production-level orchestrator for network segmentation in SCADA environments.

Rodiles Delgado, Brian G.↗

Resonant metasurface‐enabled quantum light sources for single‐photon emission and entangled photon‐pair generation

Light encodes information in multiple degrees of freedom (e.g., frequency, amplitude, and phase), enabling high‐speed, high‐bandwidth communication through fiber optics. Unlike classical light, quantum light (single or entangled photons) can transmit quantum states over long distances without loss of coherence, thereby coherently interconnecting quantum nodes for distributed quantum entanglement. Quantum light sources are critical for developing scalable quantum networks aimed at distributed quantum computing, quantum teleportation, and secure quantum communications. However, existing quantum light sources suffer from limited integrability, insufficient spectral and spatial tunability, and inefficiencies in achieving mass‐produced, deterministic, on‐demand quantum light generation. These limitations significantly hinder progress toward direct, on‐chip integration with quantum processing units and detectors – an essential step toward scalable quantum networks. Resonant metasurfaces that leverage photonic modes – such as Mie resonances, guided‐mode resonances, or symmetry‐protected bound states in the continuum – offer strong spatial and temporal confinement of electromagnetic fields, characterized by high quality factors and small mode volumes. These metasurfaces greatly enhance linear and nonlinear light‐matter interactions, making them ideal for efficient on‐chip quantum light generation and manipulation. Here, we describe recent advances in nanoscale quantum light sources and quantum photonic state manipulation enabled by resonant metasurfaces. We also provide an outlook on next‐generation miniaturized quantum light sources achievable through materials innovations in quantum emitters, the co‐design of resonant metasurfaces, and ultimately, the heterogeneous integration of emerging layered van der Waals materials with resonant metasurfaces.

71 CLASSICAL AND QUANTUM MECHANICS, GENERAL PHYSIC↗