Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “TRUST”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 289 records · Page 16

How Do We Work Together?

In essence, project management is about people. Virtually every successful project is defined by good relations between the people involved. In the same way, nearly every failed or troubled project is about poor relationships between the people involved. Let's consider one type of relationship: the one between the government and the contractor. It's easy to say that a contractor must earn the government's trust, but what does that mean in practice? Who needs to earn whose trust? What's the timeline for doing that? How does anyone know when he or she is trusted? What is the relationship supposed to be like before one feels like trust has really been established? So many questions it makes my head hurt. I have always found it better to begin a relationship assuming that everyone is trustworthy until, and unless, something occurs to belie trust.

Little, Terry↗

Human Research Program Space Human Factors Engineering (SHFE) Standing Review Panel (SRP)

The Space Human Factors Engineering (SHFE) Standing Review Panel (SRP) evaluated 22 gaps and 39 tasks in the three risk areas assigned to the SHFE Project. The area where tasks were best designed to close the gaps and the fewest gaps were left out was the Risk of Reduced Safety and Efficiency dire to Inadequate Design of Vehicle, Environment, Tools or Equipment. The areas where there were more issues with gaps and tasks, including poor or inadequate fit of tasks to gaps and missing gaps, were Risk of Errors due to Poor Task Design and Risk of Error due to Inadequate Information. One risk, the Risk of Errors due to Inappropriate Levels of Trust in Automation, should be added. If astronauts trust automation too much in areas where it should not be trusted, but rather tempered with human judgment and decision making, they will incur errors. Conversely, if they do not trust automation when it should be trusted, as in cases where it can sense aspects of the environment such as radiation levels or distances in space, they will also incur errors. This will be a larger risk when astronauts are less able to rely on human mission control experts and are out of touch, far away, and on their own. The SRP also identified 11 new gaps and five new tasks. Although the SRP had an extremely large quantity of reading material prior to and during the meeting, we still did not feel we had an overview of the activities and tasks the astronauts would be performing in exploration missions. Without a detailed task analysis and taxonomy of activities the humans would be engaged in, we felt it was impossible to know whether the gaps and tasks were really sufficient to insure human safety, performance, and comfort in the exploration missions. The SRP had difficulty evaluating many of the gaps and tasks that were not as quantitative as those related to concrete physical danger such as excessive noise and vibration. Often the research tasks for cognitive risks that accompany poor task or information design addressed only part, but not all, of the gaps they were programmed to fill. In fact the tasks outlined will not close the gap but only scratch the surface in many cases. In other cases, the gap was written too broadly, and really should be restated in a more constrained way that can be addressed by a well-organized and complementary set of tasks. In many cases, the research results should be turned into guidelines for design. However, it was not clear whether the researchers or another group would construct and deliver these guidelines.

Wichansky, Anna↗

Beyond Fair: Engagement, Data Usability, and Open Community Productivity through the NASA Open Science Data Repository

The FAIR principle (findable, accessible, interoperable, and reusable) governs the storage and sharing of NASA space biology and health data[1]. These guiding principles maximize reuse of data and the reproducibility of scientific findings. The NASA Open Science Data Repository (OSDR; an expansion of NASA GeneLab) was built on the FAIR principles and houses over 500 studies and close to 1000 datasets from decades of space life sciences experiments. OSDR embodies the FAIR principles through data governance that includes mediated, embargoed, and fully open access data. The FAIR data governance principles were recently proposed to be expanded to encompass a FAIREST framework for assessing research data repositories (FAIR + Engagement, Social connections, and Trust)[2]. FAIREST emphasizes the importance of data repositories engaging with the scientific community and gaining the trust of researchers regarding data quality. Trust also refers to the TRUST principles developed for assessment of digital repositories: Transparency, Responsibility, User Focus, Sustainability, Technology[3]. We present the “Open Science for Life in Space” Analysis Working Groups (AWGs) as evidence regarding the power of engagement, social connections, and trust which has enhanced OSDR’s capabilities and productivity. AWG members engage in two main activities. One, members provide feedback on OSDR scientific standards for data ingestion, curation, and reuse (study, subject and assay metadata; processing pipelines; dataset formats and uniformed structures for machine-readability). Two, AWG members collaborate to mine-reuse OSDR data to conduct scientific analysis. With nearly 800 active members, the AWGs have resulted in 32 publications re-using OSDR data and contributed many papers in two major special issues in Cell (2020) and Nature (2024). AWGs also serve as networking groups, facilitate social connections between researchers at all levels of experience, and also have a social online ‘Forum’ used to keep members informed on projects and opportunities. This community-centric, productive, and trustworthy data culture has resulted in a broader effect with international space agencies, academics, and the commercial space sector wanting to submit their data to OSDR. Ten studies of Inspiration 4 data were recently publicly released by OSDR, as were some JAXA human data. Coming up soon in OSDR are data submissions from the European Space Agency, Virgin Galactic PIs, and SpaceX Polaris Dawn. A major benefit of OSDR is the array of standardized and uniformly formatted data (which was developed through AWG member consensus), from which visualization tools, analysis tools, and machine learning models can be built or trained. This talk will cover the Multi-Study Visualization Tool, the Environmental Data Application, RadLab, and a UCSF-NSF funded knowledge graph biomedical health discovery tool ‘SPOKE’ currently being integrated with OSDR. OSDR also provides training programs in bioinformatics and machine learning to improve the scientific community’s awareness of data availability and to boost their ability to perform data analysis. The increasing engagement of the scientific community and the public with technologies powered by artificial intelligence (AI) heightens the need for data analysis to be transparent. The AI for Life in Space initiative leverages the data products provided in OSDR to train AI models, with an emphasis on explainable and trustworthy AI, which would not be possible without FAIR data and metadata. Overall, here we will demonstrate the importance for NASA life sciences data repositories to adhere to the FAIREST framework, by providing examples and success stories from different aspects of OSDR.

data↗

Operator Workload and Task Allocation in m:N Operational Architectures of Uncrewed Aerial Systems

Uncrewed aerial systems (UAS) show promise in urban air transport, package delivery, and emergency services. UAS efficiency can be significantly improved by having fewer operators (m) manage a greater number of vehicles (N), or the m:N architecture of operation. The current study investigates how workload affects operators’ task-allocation decision-making and potential effects of two crucial human factors: trust and self-confidence. In the context of a simulated UAS package-delivery task, 10 participants with expertise in UAS operation were recruited. Each participant reported their preferred task-allocation strategy for a set of five subtasks while watching two sets of videos with different workload levels. Perceived workload, trust, and self-confidence were also measured after each video session. Overall, participants indicated a preference for automation for most of the subtasks under the delivery mission. Trust, rather than workload and self-confidence, played a significant role in experts’ decisions of task-allocation and assignment methods. Higher trust led to higher preference for automation.

workload↗

Automating ridehailing services would reduce pooling, especially among women

Here, this study investigates how autonomous vehicles (AVs) could transform pooled (shared) ridehailing services, focusing on the impacts of fare reductions, the absence of drivers/staff, and psychological attributes such as trust in other passengers and privacy concerns. We distinguish between the automation of driving tasks and the removal of human driver/staff from the vehicle, providing novel insights into the factors influencing AV ridehailing adoption. Using a national survey with stated preference (SP) choice experiments and psychometric questions, we analyze the complex interactions of ridehailing fare, pooled ridehailing service quality, and latent attitudes on ridehailing choices. Our findings suggest that the elimination of drivers/staff from fully autonomous ridehailing could lead to a shift from pooled to solo rides, particularly among female travelers who may have greater concerns about trust and safety in unstaffed AVs. This study highlights the importance of addressing trust and comfort beyond fare discounts to ensure the inclusivity and widespread adoption of pooled AV ridehailing. These insights underscore the need for ridehailing providers and policymakers to prioritize trust-building measures, user-centered AV design that offers greater privacy, and dynamic pricing strategies, to ensure inclusive and widespread adoption of pooled AV services.

Autonomous vehicle↗

Open Radiation Monitoring: Histogram Builder Module Design

The Open Radiation Monitoring Project seeks to develop and demonstrate a modular radiation detection architecture designed specifically for use in arms control treaty verification (ACTV) applications that will facilitate rapid development of trusted systems to meet the needs of potential future treaties. A modular architecture can be used to reduce more complex systems to a series of single purpose building blocks, thereby facilitating equipment inspection and in turn building trust in the equipment by all treaty parties. Furthermore, a modular architecture can be used to control data flow within the measurement system, reducing the risk of "hidden switches" and constraining the amount of sensitive information that could potentially be inadvertently leaked. This report details the first revision of a prototype circuit that will convert analog pulses directly into a histogrammed data set for further processing. The circuit was designed with both spectroscopy and multiplicity analysis in mind but can, in principle, be used to reduce any raw data stream into a histogram. The number of output channels is limited, and the histogram bin ranges are user configurable to allow for non-uniform and discontinuous bins, which makes it possible to restrict the information being passed down stream if desired. Pulse processing relies entirely on analog circuitry and non- programmable logic, which enables operation without the need for a central processor or other programmable control unit. The circuit remains untested under the Open Radiation Monitoring project due to the closure of the sponsoring program. However, further development and testing is scheduled to take place in support of a purpose-built trusted verification system development effort known as COGNIZANT, which demonstrates the potential benefit of developing a suite of modular trusted system components.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

SAGE Intrusion Detection System: Sensitivity Analysis Guided Explainability for Machine Learning.

This report details the results of a three-fold investigation of sensitivity analysis (SA) for machine learning (ML) explainability (MLE): (1) the mathematical assessment of the fidelity of an explanation with respect to a learned ML model, (2) quantifying the trustworthiness of a prediction, and (3) the impact of MLE on the efficiency of end-users through multiple users studies. We focused on the cybersecurity domain as the data is inherently non-intuitive. As ML is being using in an increasing number of domains, including domains where being wrong can elicit high consequences, MLE has been proposed as a means of generating trust in a learned ML models by end users. However, little analysis has been performed to determine if the explanations accurately represent the target model and they themselves should be trusted beyond subjective inspection. Current state-of-the-art MLE techniques only provide a list of important features based on heuristic measures and/or make certain assumptions about the data and the model which are not representative of the real-world data and models. Further, most are designed without considering the usefulness by an end-user in a broader context. To address these issues, we present a notion of explanation fidelity based on Shapley values from cooperative game theory. We find that all of the investigated MLE explainability methods produce explanations that are incongruent with the ML model that is being explained. This is because they make critical assumptions about feature independence and linear feature interactions for computational reasons. We also find that in deployed, explanations are rarely used due to a variety of reason including that there are several other tools which are trusted more than the explanations and there is little incentive to use the explanations. In the cases when the explanations are used, we found that there is the danger that explanations persuade the end users to wrongly accept false positives and false negatives. However, ML model developers and maintainers find the explanations more useful to help ensure that the ML model does not have obvious biases. In light of these findings, we suggest a number of future directions including developing MLE methods that directly model non-linear model interactions and including design principles that take into account the usefulness of explanations to the end user. We also augment explanations with a set of trustworthiness measures that measure geometric aspects of the data to determine if the model output should be trusted.

97 MATHEMATICS AND COMPUTING↗

Open Radiation Monitoring: Conceptual System Design

The Open Radiation Monitoring (ORM) Project seeks to develop and demonstrate a modular radiation detection architecture designed specifically for use in arms control treaty verification (ACTV) applications that will facilitate rapid development of trusted systems to meet the needs of potential future treaties. Development of trusted systems to support potential future treaties is a complex and costly endeavor that typically results in a purpose-built system designed to perform one specific task. The majority of prior trusted system development efforts have relied on the use of commercial embedded computers or microprocessors to control the system and process the acquired data. These processors are complex, making authentication and certification of measurement systems and collected data challenging and time consuming. We believe that a modular architecture can be used to reduce more complex systems to a series of single-purpose building blocks that could be used to implement a variety of detection modalities with shared functionalities. With proper design, the functionality of individual modules can be confirmed through simple input/output testing, thereby facilitating equipment inspection and in turn building trust in the equipment by all treaty parties. Furthermore, a modular architecture can be used to control data flow within the measurement system, reducing the risk of "hidden switches" and constraining the amount of sensitive information that could potentially be inadvertently leaked. This report documents a conceptual modular system architecture that is designed to facilitate inspection in an effort to reduce overall authentication and certification burden. As of publication, this architecture remains in a conceptual phase and additional funding is required to prove out the utility of a modular architecture and test the assumptions used to rationalize the design.

61 RADIATION PROTECTION AND DOSIMETRY↗

Motivation and Design of the OCPP Security Service

Pacific Northwest National Laboratory is conducting in-depth research aimed at exploring how zero trust security principles can be effectively applied to electric vehicle charging infrastructure. This investigation seeks to enhance the resilience and reliability of these systems against cyber threats, ensuring secure and uninterrupted access to charging services for electric vehicle users and electric supply. Zero trust is a security concept centered on the belief that system operators should not automatically trust users or systems based on their location, whether inside or outside the organization, but instead must verify everything trying to connect to their systems before granting access. A key aspect of the project is to demonstrate and validate zero trust approaches targeted to electric vehicle (EV) charging infrastructure. It has been observed that both open-source and commercial solutions often overlook the specific protocols employed in managing EV charging stations and proceeded with a general, protocol-agnostic approach. While these strategies effectively block non-authorized routes to the charging infrastructure, they do not tackle the situations where attackers may exploit legitimate access channels, such as the inattentive operator model posited by the Idaho National Laboratory. To address this gap, this paper proposes and discusses a new security service targeted to the Open Charge Point Protocol (OCPP), which is the de facto protocol for the management of charging stations and serves a critical role in the broader adoption of electric vehicles. The design and architecture of the proposed OCPP security service are discussed in detail, outlining how it aims to safeguard charging station management system (CSMS) functions. The service is particularly important in scenarios where the charging station operator (CSO), responsible for the maintenance and operation of charging stations, and the charging network provider (CNP), which manages the charging network's accessibility and billing, are separate entities. This distinction is crucial because CSOs and CNPs often have different priorities, objectives, and operational responsibilities, which may not always align perfectly. For instance, a CSO might prioritize uptime and customer satisfaction, while a CNP might focus on maximizing revenue and network utilization. Such misalignment can create security vulnerabilities, as each entity might implement different policies and standards, potentially leaving gaps in the overall security posture.

33 ADVANCED PROPULSION SYSTEMS↗

Moving beyond post hoc explainable artificial intelligence: a perspective paper on lessons learned from dynamical climate modeling

AI models are criticized as being black boxes, potentially subjecting climate science to greater uncertainty. Explainable artificial intelligence (XAI) has been proposed to probe AI models and increase trust. In this review and perspective paper, we suggest that, in addition to using XAI methods, AI researchers in climate science can learn from past successes in the development of physics-based dynamical climate models. Dynamical models are complex but have gained trust because their successes and failures can sometimes be attributed to specific components or sub-models, such as when model bias is explained by pointing to a particular parameterization. We propose three types of understanding as a basis to evaluate trust in dynamical and AI models alike: (1) instrumental understanding, which is obtained when a model has passed a functional test; (2) statistical understanding, obtained when researchers can make sense of the modeling results using statistical techniques to identify input–output relationships; and (3) component-level understanding, which refers to modelers' ability to point to specific model components or parts in the model architecture as the culprit for erratic model behaviors or as the crucial reason why the model functions well. We demonstrate how component-level understanding has been sought and achieved via climate model intercomparison projects over the past several decades. Such component-level understanding routinely leads to model improvements and may also serve as a template for thinking about AI-driven climate science. Currently, XAI methods can help explain the behaviors of AI models by focusing on the mapping between input and output, thereby increasing the statistical understanding of AI models. Yet, to further increase our understanding of AI models, we will have to build AI models that have interpretable components amenable to component-level understanding. We give recent examples from the AI climate science literature to highlight some recent, albeit limited, successes in achieving component-level understanding and thereby explaining model behavior. The merit of such interpretable AI models is that they serve as a stronger basis for trust in climate modeling and, by extension, downstream uses of climate model data.

54 ENVIRONMENTAL SCIENCES↗

The Astronaut Glove Challenge: Big Innovation from a (Very) Small Team

Many measurements were taken by test engineers from Hamilton Sundstrand, the prime contractor for the current EVA suit. Because the raw measurements needed to be converted to torques and combined into a final score, it was impossible to keep track of who was ahead in this phase. The final comfort and dexterity test was performed in a depressurized glove box to simulate real on-orbit conditions. Each competitor was required to exercise the glove through a defined set of finger, thumb, and wrist motions without any sign of abrasion or bruising of the competitor's hand. I learned a lot about arm fatigue! This was a pass-fail event, and both of the remaining competitors came through intact. After taking what seemed like an eternity to tally the final scores, the judges announced that I had won the competition. My glove was the only one to have achieved lower finger-bending torques than the Phase VI glove. Looking back, I see three sources of the success of this project that I believe also operate in other programs where small teams have broken new ground in aerospace technologies. These are awareness, failure, and trust. By remaining aware of the big picture, continuously asking myself, "Am I converging on a solution?" and "Am I converging fast enough?" I was able to see that my original design was not going to succeed, leading to the decision to start over. I was also aware that, had I lingered over this choice or taken time to analyze it, I would not have been ready on the first day of competition. Failure forced me to look outside conventional thinking and opened the door to innovation. Choosing to make incremental failures enabled me to rapidly climb the learning curve. Trusting my "gut" feelings-which are really an internalized accumulation of experiences-and my newly acquired skills allowed me to devise new technologies rapidly and complete both gloves just in time. Awareness, failure, and trust are intertwined: failure provides experiences that inform awareness and provide decision-making opportunities that build trust among team members and managers while opening minds to new pathways for development. All three are necessary for teams-large or small-to achieve big innovation.

Homer, Peter↗

Proceedings of the Third International Workshop on Proof-Carrying Code and Software Certification

This NASA conference publication contains the proceedings of the Third International Workshop on Proof-Carrying Code and Software Certification, held as part of LICS in Los Angeles, CA, USA, on August 15, 2009. Software certification demonstrates the reliability, safety, or security of software systems in such a way that it can be checked by an independent authority with minimal trust in the techniques and tools used in the certification process itself. It can build on existing validation and verification (V&V) techniques but introduces the notion of explicit software certificates, Vvilich contain all the information necessary for an independent assessment of the demonstrated properties. One such example is proof-carrying code (PCC) which is an important and distinctive approach to enhancing trust in programs. It provides a practical framework for independent assurance of program behavior; especially where source code is not available, or the code author and user are unknown to each other. The workshop wiII address theoretical foundations of logic-based software certification as well as practical examples and work on alternative application domains. Here "certificate" is construed broadly, to include not just mathematical derivations and proofs but also safety and assurance cases, or any fonnal evidence that supports the semantic analysis of programs: that is, evidence about an intrinsic property of code and its behaviour that can be independently checked by any user, intermediary, or third party. These guarantees mean that software certificates raise trust in the code itself, distinct from and complementary to any existing trust in the creator of the code, the process used to produce it, or its distributor. In addition to the contributed talks, the workshop featured two invited talks, by Kelly Hayhurst and Andrew Appel. The PCC 2009 website can be found at http://ti.arc.nasa.gov /event/pcc 091.

Ewen, Denney, W.↗

Towards Explainability of UAV-Based Convolutional Neural Networks for Object Classification

f autonomous systems using trust and trustworthiness is the focus of Autonomy Teaming and TRAjectories for Complex Trusted Operational Reliability (ATTRACTOR), a new NASA Convergent Aeronautical Solutions (CAS) Project. One critical research element of ATTRACTOR is explainability of the decision-making across relevant subsystems of an autonomous system. The ability to explain why an autonomous system makes a decision is needed to establish a basis of trustworthiness to safely complete a mission. Convolutional Neural Networks (CNNs) are popular visual object classifiers that have achieved high levels of classification performances without clear insight into the mechanisms of the internal layers and features. To explore the explainability of the internal components of CNNs, we reviewed three feature visualization methods in a layer-by-layer approach using aviation related images as inputs. Our approach to this is to analyze the key components of a classification event in order to generate component labels for features of the classified image at different layers of depths. For example, an airplane has wings, engines, and landing gear. These could possibly be identified somewhere in the hidden layers from the classification and these descriptive labels could be provided to a human or machine teammate while conducting a shared mission and to engender trust. Each descriptive feature may also be decomposed to a combination of primitives such as shapes and lines. We expect that knowing the combination of shapes and parts that create a classification will enable trust in the system and insight into creating better structures for the CNN.

Dolph, Chester V.↗

Analyzing Natural Language Context in Human-Machine Teaming using Supervised Machine Learning

Building a foundation for trustworthiness and trust verification in multi-asset teaming is the research challenge of Autonomy Teaming and TRAjectories for Complex Trusted Operational Reliability (ATTRACTOR). The Design Reference Mission (DRM) for ATTRACTOR is a search and rescue mission objective governed by a multi-member team consisting of human and machine operators. A crucial component to the effort is the communication between humans and autonomous agents throughout both planning and execution stages of the mission. Intuitive communication methods and modalities are posited as critical enablers for certifying trust and trustworthiness. This paper reports on the data collection and analysis conducted in support of the Human Informed Natural-language GANs Evaluation (HINGE)project to attain explainable and trusted communication between human-machine assets. Two identically curated image description datasets were acquired for HINGE, both consisting of two unique input modalities (typed vs. verbal) and retrieved in two distinct contexts (general vs. specific). The gathered datasets were assessed and compared using Parts-of-Speech (POS)features, sentence similarity metrics, and linguistic analysis. Then, the datasets were modeled and tested separately and in combination with one another using machine learning algorithms. The comparison and testing results reveal a superior dataset, by which a preferred context and input is understood, for generating image representations of missing persons using a Generative Adversarial Network (GAN).

Bryan A Barrows↗

A Distributed Simulation-to-Flight Framework to Support Investigating Trust/Trustworthiness in Multi-Agent Systems

As autonomous systems continue to grow both in use and complexity, the necessity for robust and extensible simulation-to-flight frameworks is paramount for establishing an effective architecture for autonomous systems. Hardware test flights are time-consuming and cost prohibitive during early system design and development. Simulation environments can be useful tools to accelerate algorithm development and testing. However, transitions from simulation to flight (sim-to-flight) can be challenging, unless systems are designed with this transition in mind and with the necessary capabilities built into the architecture and framework. One of the objectives of Autonomy Teaming and TRAjectories for Complex Trusted Operational Reliability (ATTRACTOR) was to design and develop a distributed mixed-reality simulation environment to begin establishing a basis for certification of autonomous systems via research into trust and trustworthiness. ATTRACTOR’s objective was to construct computational concepts of trustworthiness and justifiable trust in multi-agent autonomous teams, to inform future certification of safety-critical and time-critical autonomous systems in aviation. In this paper, we present an autonomous systems architecture and development framework paired with a persistent distributed modeling and simulation (ModSim) environment for test and evaluation of autonomous systems. They were designed under ATTRACTOR in order to measure and establish trustworthiness and trust in single-and multi-agent human-machine systems whether these machines are fixed-wing general aviation, rotary-wing Unmanned Aerial Vehicles (UAVs), ground rovers, or even spacecraft. The Autonomous Entity Operational Network (AEON) framework enables autonomous system development with an easily extensible collection of libraries and plug-n-play nodes facilitated by the Data Distribution Service (DDS) communication protocol standard. The Baseline Environment for Autonomous Modeling (BEAM) simulation environment is a distributed mixed-reality Unity™-based environment built around the same DDS communication paradigm allowing for easy integration with AEON-based autonomous applications, enabling sim-to-flight with minimal configuration changes. Using AEON and BEAM, source code that runs in simulation ports directly to hardware and has successfully flown in the National Airspace System (NAS) at NASA LaRC many times over the lifetime of ATTRACTOR.

Benjamin N Kelley↗

WWAO-WSWC Workshop Report 2019 Final

EXECUTIVE SUMMARY The Western States Water Council (WSWC) and the NASA Western Water Applications Office (WWAO) hosted a joint workshop on technology transfer for water management in the Western U.S. The goals of the workshop were to understand how different agencies approach the technology transfer and research to operations (R2O) process, identify best practices, and discuss existing barriers to successful technology infusion into operational water resource management systems at the state and federal level. The workshop took place August 7-9, 2019 in Irvine, CA. Key outcomes of the meeting include the following:• U.S. Rep. Grace Napolitano provided opening remarks for the workshop, where she highlighted the critical value of water data and the importance of collaboration between state and federal agencies in working to advance the use of water data in water management, planning and policy. • A total of 33 participants (including remote participants) were part of the workshop. They included principal investigators and project teams supported by NASA (Cyanobacteria Assessment Network, Evapotranspiration for Western States, Evaporative Stress Index, the Airborne Snow Observatory, Satellite-based Snow Water Equivalent in the Sierra Nevadas, and Fallowed Area Mapping) as well as representatives from federal (USGS, NOAA, USBR, EPA) and state (CA, WY, OR, NE) agency partners. • One main outcome of the meeting was the consensus that successful transitions of new applications and new technologies into operations require careful planning, effective communication within and across institutions, resources and considerable time investments. In addition, there was broad agreement that significant lead time is often required to allow for identification of financial and technical resources to sustain operational use of new data, information and tools.• The meeting included remarks from U.S. Rep. Napolitano and discussions during presentations and breakout groups about key opportunities to develop best practices and streamline the technology transfer process. • For example, one key set of best practices that emerged revolved around the the importance of building trust and establishing clear lines of communication between the research and operational institutions. The conversations led to defining two key components of trust-building. The first aspect is purely technical. It requires effectively demonstrating that the proposed application meets the end user’s needs in terms of accuracy, format, resolution, latency, metadata and documentation. The second aspect of building trust involves developing sustained, productive and mutually-beneficial relationships with the partner operational agency. The best practices presented here span both the technical as well as the relational aspects of cultivating trust. • This workshop served as a first step in developing a broader community discussion around R2O in western water management. Many of the best practices and lessons learned described in this report represent starting places for action within the WWAO, WSWC and our colleagues’ institutions. • Effective implementation of the best practices that emerged from this workshop will require sustained investments of time, resources and transition planning. In recognition of this, the WSWC and the WWAO proposed continuation of discussions begun at the workshop through a series of semi-annual or annual workshops.

Wilardson, Tony↗

Enabling Design Space Exploration for RISC-V Secure Compute Environments

Cycle-level architectural simulation of Trusted Execution Environments (TEEs) can enable extensive design space exploration of these secure architectures. Existing architectural simulators which support TEEs are either based on hardware-level implementations or abstract analytic models. In this paper, we describe the implementation of the gem5 models necessary to run and evaluate the RISC- V-based open source TEE, Keystone, and we discuss how this simulation environment opens new avenues for designing and studying these trusted environments. We show that the Keystone simulations on gem5 exhibit similar performance as the previous hardware evaluations of Keystone. We also describe three simple example use cases (understanding the reason of trusted execution slowdown, performance of memory encryption, and micro-architecture impact on trusted execution performance) to demonstrate how the ability to simulate TEEs can provide useful information about their behavior in the existing form and also with enhanced designs.

97 MATHEMATICS AND COMPUTING↗

Continuous variable quantum secret sharing

Continuous variable quantum secret sharing (CV-QSS) technologies are described that use laser sources and homodyne detectors. Here, a Gaussian-modulated coherent state (GMCS) prepared by one device passes through secure stations of other devices sequentially on its way to a trusted device, and each of the other devices coherently adds a locally prepared, independent GMCS to the group of propagating GMCSs. Finally, the trusted device measures both the amplitude and the phase quadratures of the received group of coherent GMCSs using double homodyne detectors. The trusted device suitably uses the measurement results to establish a secure key for encoding secret messages to be broadcast to the other devices. The devices cooperatively estimate, based on signals corresponding to their respective Gaussian modulations, the trusted device's secure key, so that the cooperative devices can decode the broadcast secret messages with the secure key.

97 MATHEMATICS AND COMPUTING↗