Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “refresh”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 343 records · Page 19

Crew Medical Training to Progressively Enable EIMO

Background. Onboard medical capabilities have greatly expanded over the history of the US space program. Newly identified space-related medical conditions, technological advances, and longer mission durations have led to an increasing need for on-demand medical expertise. Lengthy communications delays, lack of resupply and evacuation opportunities on exploration-class missions place an ever-increasing burden on the crew to provide medical care. Having adequate knowledge, skills, and abilities (KSA) available is an essential component of successful Earth Independent Medical Operations (EIMO). Without appropriate crew training and KSA, cutting-edge medical equipment has little value. Presumably, the crew will include a qualified physician; however, if the physician is incapacitated, a non-physician crew medical officer (CMO) will be needed. While more crew time is needed for medical training, there will be concomitant increases in preflight training demands for vehicle system management, operations, science, and contingencies. In truly independent operations, onboard resources such as just-in-time training, mixed reality, decision support tools, and AI-enabled chatbot “consultants” will be needed to augment KSA. Overview. Because of crew time constraints, topical priorities must be determined for preflight training. Curricula should be developed that emphasize management of conditions with relatively high incidence and morbidity/mortality. Defining the required KSA levels to treat each condition is essential, but all crewmembers should have basic lifesaving skills. Procedural and diagnostic training on live patients and simulators should be prioritized over classroom lectures. Crews must be trained with onboard equipment, resources, mixed reality, and AI-based decision support tools. Mission simulations should include medical problems with/without ground support and with appropriate communication delays. Certification guidelines for each level of KSA must be established. Skills rapidly decay for non-physician CMO’s; both pre-flight and in-flight refresher training will be needed. During spaceflight just-in-time training, simulations, and onboard CME with crew physician can help retain skills. Discussion. Medical technology, simulation design, mixed reality, and AI are advancing at a dizzying rate. Recognizing the severe constraints on crew time, it is critical that astronaut training is highly efficient and adapted to keep pace with new innovations both pre-flight and during exploration missions. These challenges will be discussed during this panel session.

Jay Lemery↗

New Development Activities at NASA Ames in Reusable TPS Materials

Over the last few years, new activities in rapid, low-cost access to low-earth orbit (LEO) and hypersonic flight have refreshed interest in reusable thermal protection systems (RTPS) that have not had broad application since the Space Shuttle era. Development of novel systems having a greater consideration of full cycle cost (lower cost raw materials, manufacturing, integration, and refurbishment) in addition to improved performance are needed to enable this new generation of space flight. NASA Ames has a long history of RTPS development including invention of flexible blankets such as Advanced Flexible Reusable Surface Insulation (AFRSI), rigid ceramic tiles like Fibrous Refractory Composite Insulation (FRCI) and Alumina Enhanced Thermal Barrier (AETB), and multi-component systems like Toughened Uni-piece Fibrous Reinforced Oxidation-resistant Composite (TUFROC). In much more recent times, NASA Ames is supporting the growing commercial space field through internal research and development efforts for high-risk low TRL materials and collaboration with commercial partners including technology transfer. This talk will discuss the current development efforts that span broadly from updating legacy insulating systems with modern raw materials and processes to totally novel designs for heat pipes with various low-TRL activities in between. It will also discuss Ames’ recent re-investment in experimental capabilities to enable characterization and material testing.

Reusable thermal protection materials↗

Investigating the Spatial and Temporal Limitations for Remote Sensing of Wildfire Smoke Using Satellite and Airborne Imagers During FIREX_AQ

Starting from point sources, wildfire smoke is important in the global aerosol system. The ability to characterize smoke near-source is key to modeling smoke dispersion and predicting air quality. With hemispheric views and 10-min refresh, imagers in Geostationary (GEO) orbit have advantages monitoring smoke over once-per-day sensors in low-earth orbit (LEO). However, both can be inadequate in capturing the characteristics of smoke plumes close to their sources due to too-coarse spatial resolution (both detector and product resolution), too-sparse temporal resolution (from LEO sensors), and too-conservative masking. In addition to satellite observations, the Fire Influence on Regional to Global Environments and Air Quality experiment offered sub-orbital enhanced-MODIS Airborne Simulator (eMAS) imagery at 50 m pixel resolution—including multiple eMAS flight tracks over individual fires in short time periods. It provided opportunity to explore smoke plume characterization at various spatial and temporal scales and quantify the limitations of space sensors for describing smoke magnitude near source as well as its temporal evolution. Here we applied modified aerosol algorithm to different imagers, relaxing its masking to estimate smoke's aerosol optical depth (AOD) as close as possible to its source. We found that GEO sensors with nominal 1 km spatial resolution can match the much finer resolution eMAS retrieved mean plume AOD, as long as the retrieval spatial resolution is finer than the width of the plumes. However, the plume's maximum AOD may be drastically underestimated by satellite products.

remote sensing↗

NASA Earth Systems Digital Twins (ESDT)

"Similarly to artificial intelligence, which is now revolutionizing many aspects of our daily lives, Earth system digital twin technologies have the potential to revolutionize the way Earth Science research will be conducted in the future, and how results and knowledge from this research will provide information to support decision making and yield impactful societal benefits. An Earth System Digital Twin or ESDT is a dynamic and interactive information system that first provides a digital replica of the past and current states of the Earth or Earth system as accurately and timely as possible; second, allows for computing forecasts of future states under nominal assumptions and based on the current replica; and third, offers the capability to investigate many hypothetical scenarios under varying impact assumptions. In other words, an ESDT provides the integrated What-Now, What-Next, and What-If pictures of the Earth or Earth system, by continuously ingesting newly observed data and by leveraging multiple interconnected models, machine learning as well advanced computing and visualization capabilities. Digital twins have been developed in engineering since 2002, but the interest in digital twins for the Earth domain is more recent and stems from the convergence of several developments: - The huge amount of diverse data that has now been collected continuously for more than 50 years, and that is becoming more and more difficult to access, understand, and utilize. - At the same time, because of climate change and its impacts the information produced by all of this data is becoming of interest to many new non-traditional users for analyzing and predicting various phenomena. - Because of advances in computational and visualization capabilities and the parallel unprecedented development of machine learning (ML), extracting relevant information from these large amounts of data and running complex models faster has become possible. As a result, it is becoming necessary and possible to build intuitive and interactive frameworks that will enable users with various skill levels and/or organizational hierarchy levels to easily access large amounts of targeted information along with the relevant tools and models (Earth system and human activity models), to support them in analyzing and visualizing this information, to help them understand interactions among models, to visualize the potential outcomes of various impacts, and to support decision or policy making. The full power of digital twins is that, through an integrated representation and standardized tools and software technologies, the same digital replica can address the needs of multiple users at various resolutions (spatial and temporal) and for various applications (science, economic, policy, etc.) – “from farmer to scientist”. With all these interests at stake, the challenges of building optimal digital twins are many and complex. The first challenge is to determine if a Digital Twin should be global or local, and multi-domain or thematic. For example, some domains such as Climate or Weather will require a global Digital Twin or Digital Twin capabilities while science areas such as Biodiversity might be more local. We can also envision that multiple thematic ESDTs, e.g., Air Quality, Wildfires, Hydrology could be federated or provide input to other ESDTs, either on a regional level or to a more global ESDT. Overall, we can imagine a future “web” of Digital Twins co-existing in a hierarchy or in a network, and capable of being connected or federated depending on the needs. This last point brings up the very important challenge of interoperability, including standards and protocols that will need to be built into these systems from the beginning. Each individual digital twin would have full flexibility in internal construction but would need standards-based interfaces (input and output) or hooks to make it compatible with others. Another challenge when building digital twins will be to decide how to organize each digital replica. Based on the applications targeted by the DT under implementation, various amounts and types of raw data, Analysis Ready Data (ARD) and information will need to be incorporated. Depending on the required latencies and needs of the users, various solutions can be considered, including Data Cubes, Data Lakes, pointers, or computing information on demand. We envision that each ESDT will choose a solution adapted to its specific objectives. Another important challenge is the type(s) of visualization that will be used, as well as the level of interactivity and refresh rate that will be required. Again, this will depend on the objectives of the ESDT, but also on the various users’ needs. In most cases, several types of visualizations and human interfaces will need to be offered depending on the projected users of that system. In parallel to the challenges highlighted above, there are also many tools and technologies that will need to be developed or improved for all types of digital twins. Among those are improved machine learning technologies, for example providing explainability, but also ML techniques for causality and providing a better integration of physics models. Additionally, reliable uncertainty quantification methods will be needed for all ESDT components, from validating data fusion and assimilation to assessing the accuracy of ML models and weighing the values of decisions supported by those systems. This presentation introduces the ESDT concept, presents several ESDT use cases, and a proposed ESDT architecture framework, as well as various technologies being developed by the Advanced Information Systems Technology (AIST) Program."

Earth Science Remote Sensing; Information Systems↗

New Development Activities at NASA Ames in Reusable TPS Materials

Over the last few years, new activities in rapid, low-cost access to low-earth orbit (LEO) and hypersonic flight have refreshed interest in reusable thermal protection systems (RTPS) that have not had broad application since the Space Shuttle era. Development of novel systems having a greater consideration of full cycle cost (lower cost raw materials, manufacturing, integration, and refurbishment) in addition to improved performance are needed to enable this new generation of space flight. NASA Ames has a long history of RTPS development including invention of flexible blankets such as Advanced Flexible Reusable Surface Insulation (AFRSI), rigid ceramic tiles like Fibrous Refractory Composite Insulation (FRCI) and Alumina Enhanced Thermal Barrier (AETB), and multi-component systems like Toughened Uni-piece Fibrous Reinforced Oxidation-resistant Composite (TUFROC). In much more recent times, NASA Ames is supporting the growing commercial space field through internal research and development efforts for high-risk low TRL materials and collaboration with commercial partners including technology transfer. This talk will discuss the current development efforts that span broadly from updating legacy insulating systems with modern raw materials and processes to totally novel designs for heat pipes with various low-TRL activities in between. It will also discuss Ames’ recent re-investment in experimental capabilities to enable characterization and material testing.

Reusable thermal protection materials↗

Boundary-Layer Cloud Modeling Challenges on the North Slope of Alaska

The accurate modeling and prediction of cloud base heights is critical for energy balance calculations and aviation operations, alike. Low-level (i.e., boundary-layer) Arctic clouds can be difficult to model, making prediction of formation and dissipation challenging. Primarily mixed-phase, these clouds typically contain low quantities of supercooled liquid water and often slowly precipitate relatively small amounts of moderately and heavily rimed snow particles. While this appears to be the predominant cloudy state on the North Slope of Alaska (NSA), the delicate balance of microphysical, dynamical, radiative, surface coupling, and advective processes can rapidly shift to heavy snow (with various degrees of riming) or to a complete dissipation of the cloud layer without any precipitation, depending on the dominant processes. Here we strive to disentangle these various processes. First, we compare the predictive performances of four different numerical weather models in forecasting the presence and base-heights of low-level clouds: the High-Resolution Rapid Refresh - Alaska (HRRR-AK) model, the Polar Weather Research and Forecasting (Polar WRF) model, the Unified Model (UM), and the European Centre for Medium-range Weather Forecasting (ECMWF) model. Initial results comparing model output at two U.S. Department of Energy Atmospheric Radiation Measurement (AMT) NSA sites, during the fall season in 2019 and 2022, show that the UM slightly outperforms the HRRR-AK in terms of accurately forecasting the presence of a low-level cloud layer (89% of the time). All models have a significant bias of 300 to 800 meters in forecasting cloud base height (lower than is observed); however, the UM and ECMWF models have the lowest biases. Finally, a case study for a particularly challenging April 2017 thin-cloud event is presented, wherein we compare the performance of four different bulk microphysical parameterization schemes using a higher-resolution large eddy simulation (LES) model, the WRF-LES. Initial results show that the Thompson scheme was the only one able to reproduce and sustain a substantial supercooled liquid layer, but it was unable to reproduce the transition from a deep, liquid-rich cloud to a thin layer with moderately and heavily rimed precipitation. This is the first step in linking simulated LES-scale riming processes with those parameterized at a coarser mesoscale model scale. This has important implications for forecasting low-level clouds in an operational environment, given the efficiency of the riming process.

cloud base heights↗

Lessons Learned from NASA Goddard Space Flight Center’s Product Development Lead Training Schedule and Cost Development Workshop: Continuous Improvement

This presentation provides a status of the Goddard Space Flight Center (GSFC) effort to increase foundational knowledge of Product Development Leads (PDLs) in schedule and cost management including earned value management (EVM). In 2012, GSFC’s Engineering and Technology Directorate (ETD) implemented an in-house training program to prepare PDLs for managing the technical, cost, schedule, and risk aspects of spaceflight systems to meet their subsystem commitments. Developed in-house, the PDL training program provides an integrated approach to requirements development, risk, schedule and cost management, EVM, performance tracking, and other areas. The program has been held twice yearly since its inception with 531 participating and 451 completing the curriculum. In 2017, the program won the Robert H. Goddard award for Quality and Process Improvement. Program development and evolution were presented in the 2018 NASA Schedule and Cost Symposium. The presentation was so well received that this year we focus on one workshop within the program: Schedule and Cost Development, including EVM. We examine the on-going logic modeling process and how participant and stakeholder data influence workshop content and design, and how the disciplines of schedule and cost contribute to mission success. In this presentation we refresh you on how the approach integrates lecture, small group discussion, estimating, case study exercises, and problem solving. We update you on the data collected from participants and stakeholders, and we discuss how we use these data to measure training effectiveness. Specific topics include: • How the logic model is used as the backbone for continuous program improvement, • How feedback influences implementation and curriculum updates, • How data collection and analysis inform workshop content and development, including participant discoveries of EVM data, • How including the resource analyst and planner in the product development team supports project success.

Lessons Learned↗

Cloud Top Phase Characterization of Extratropical Cyclones over the Northeast and Midwest United States: Results from IMPACTS

Cloud top phase (CTP) impacts cloud albedo and pathways for ice particle nucleation, growth, and fallout within extratropical cyclones. This study uses airborne lidar, radar, and Rapid Refresh analysis data to characterize CTP within extratropical cyclones as a function of cloud top temperature (CTT). During the 2020, 2022, and 2023 Investigation of Microphysics and Precipitation for Atlantic Coast-Threatening Snowstorms (IMPACTS) field campaign deployments, the Earth-Resources 2 (ER-2) aircraft flew 26 research flights over the Northeast and Midwest U.S. to sample the cloud tops of a variety of extratropical cyclones. A training dataset was developed to create probabilistic phase classifications based on Cloud Physics Lidar measurements of known ice and liquid clouds. These classifications were then used to quantify dominant CTP in the top 150 m of clouds sampled by the Cloud Physics Lidar in storms during IMPACTS. Case studies are presented illustrating examples of supercooled liquid water at cloud top at different CTT ranges (-3°C -20°C. Liquid-bearing cloud tops were found at CTTs as cold as -37ºC.

Troy J. Zaremba↗

Exploration Medical Integrated Product Team Clinical Decision Support Market Survey

NASA’s Exploration Medical Integrated Product Team (XMIPT) has identified Clinical Decision Support (CDS) technology as a critical need for future human space exploration. Such technology will support real time diagnosis, monitoring, and treatment of spaceflight medical conditions. The need for such tools and support systems is critical for in-mission clinical decision-making, especially when Earth-based support is unavailable due to communication delays or blackouts. Supporting technologies may or may not involve Artificial Intelligence (AI), and would support astronaut crew with minimal clinical training, or even those with advanced training if they are, for example, in need of a refresher, experiencing multiple stressors, or temporarily overloaded with tasking. This need traces to the Development of Earth Independent Operations Technologies for NASA’s Mars Campaign Office. The CDS Market Survey purpose, methods, outcomes thus far, and near-term steps will be discussed.

Decision support↗

Probabilistic Day-Ahead Forecasting Using an Analog Ensemble Approach for Wind Farm Grid Services

Wind resource assessment and wind power forecasting are used in research and industry to anticipate future power output at scales ranging from individual wind turbines to entire wind farms. Probabilistic day-ahead wind forecasting is useful for anticipating how a wind farm could potentially participate in the day-ahead market by providing upper and lower bounds for expected power generation, thus informing grid operators of its uncertainty. Understanding this uncertainty is part of a larger project focused on building a platform that combines efforts in weather forecasting, aerodynamic and economic modeling to create maximum value of a wind plant to better provide services to the grid. This effort is also known as the Atmosphere to Electrons to Grid (A2E2G) project. One method for producing a probabilistic forecast is through the analog ensemble approach (Delle Monache et al., 2011). This method leverages historical forecasts and their corresponding observations as a training data set from which future forecasts can be made. For some future forecast, the most similar historical forecasts (analogs) are identified on a regular time basis such as once per a 3-hour window. The most similar analogs, based on a metric such as root mean square error (RMSE), are recorded and their corresponding verifying observations are used as an ensemble member for this future forecast. Prior work in this area demonstrates improvements over raw Numerical Weather Prediction (NWP) forecasts and shows skill similar to techniques such as logistic regression and machine learning (Delle Monache et al., 2013; Alessandrini et al., 2015). Here, we take the High-Resolution Rapid Refresh model (HRRR) day-ahead forecast (0-36 hours) to create a probabilistic day-ahead forecast using an analog ensemble approach. The HRRR has an hourly temporal resolution, with a spatial resolution of 3 km. The 12 UTC HRRR model run is downloaded every day for one year from August 2019 - July 2020, with the first 11 months serving as a bank of analogs from which the forecasting algorithm can create a probabilistic forecast. Once downloaded, the original HRRR forecast is temporally interpolated to 5-minutes, aligning with both the temporal resolution of the observations as well as the timescale relevant for day-ahead power forecasts. The forecast is validated at the M2 tower at the Flatirons Campus of the National Renewable Energy Laboratory (NREL) at a typical wind turbine height of 80 m. Variables such as wind speed, wind direction, and turbulence intensity are incorporated into the probabilistic forecast model and weighted according to their relative importance to the forecast. Based on metrics such as mean bias error (MBE), mean absolute error (MAE), and root mean square error, the analog ensemble forecast outperforms the raw HRRR forecast during the testing period of July 2020. Figure 1 illustrates an example day-ahead forecast compared against the verifying observations. The general variability and ramps are captured throughout the day, with potential to further improve the analog ensemble model through machine learning techniques.

numerical weather prediction↗

Register-Like Block RAM: Implementation, Testing in FPGA and Applications for High Energy Physics Trigger Systems

In high energy physics experiment trigger systems, block memories are utilized for various purposes, especially in indexed searching algorithms. It is often demanded to globally reset all memory locations between different events which is a feature not supported in regular block memories. Another common demand is to be able to update the contents in any memory location in a single clock cycle. These two demands can be fulfilled with registers but the cost of using registers for large memory is unaffordable. In this paper, a register-like block memory design scheme is described, which allows updating memory locations in single clock cycle and effectively refreshing entire memory within a single clock. The implementation and test results are presented.

72 PHYSICS OF ELEMENTARY PARTICLES AND FIELDS↗

Modernizing the SNS Control System

The Spallation Neutron Source at Oak Ridge National Laboratory has been operating since 2006. An upgrade to double the machine power from 1.4 MW to 2.8 MW is currently underway and a project to add a second target station is in the preliminary design phase. While each project will add the controls needed for their specific scope, the existing control system hardware, software, and infrastructure require upgrades to maintain high availability and ensure the system will meet facility requirements into the future. While some systems have received new hardware due to obsolescence, much of the system is original apart from some maintenance and technology refresh. Software will also become obsolete and must be upgraded for sustainability. Further, requirements for system capacity can be expected to increase as more subsystems upgrade to smarter devices capable of higher data rates. This paper covers planned improvements to the integrated control system with a focus on reliability, sustainability, and future capability.

White, Karen S.↗

Forecasting Dynamic Line Rating with Spatial Variation Considerations

Dynamic line rating (DLR) is a technology that allows the ampacity of an electrical conductor to be calculated using real-time or forecasted weather conditions. Historically, the ampacity of a conductor has been determined using a static line rating method which assumes conservative weather assumptions. Therefore, not only can DLR give a more accurate measurement of the true ampacity of a conductor, but it can also increase its ampacity during weather conditions with greater thermal mitigations. The two primary cooling factors in the ampacity calculations are wind speed and direction. In complex terrain, wind speed and direction can have large variations over short distances. Therefore, accurately identifying the limiting span of a transmission line requires high spatial resolution of the wind along its path. One solution is to install dense weather stations along their path, though this can become costly over long distances. Therefore, researchers have investigated the use of Computation Fluid Dynamic (CFD) simulations to accurately compute the wind field along the path of a transmission line and use these results to identify the limiting section of the conductor. This work presents a case study that evaluates the coupling of CFD simulations and forecasted weather simulations using the High-Resolution Rapid Refresh (HRRR) model points over a 2-year span within a region in south eastern Idaho. The primary goal of the work is the evaluation of the number of HRRR model points used, i.e., weather stations, along the path of the line and the accuracy of the resulting DLR ampacity. This was done using 4, 10, 17, 26, and 35 HRRR model points along two transmission line paths. The results indicate that as the number of model points are increased, the DLR ampacity of the lines decrease, yet converge as more points are added and demonstrate little change with additional HRRR points. It is expected that these results can help transmission line operators identify the number of weather stations that must be installed when coupled with CFD simulations and DLR ampacity to ensure accurate ratings and safe operations.

17 WIND ENERGY↗

Forecasting Dynamic Line Rating with Spatial Variation Considerations

Dynamic line rating (DLR) is a technology that allows the ampacity of an electrical conductor to be calculated using real-time or forecasted weather conditions. Historically, the ampacity of a conductor has been determined using a static line rating method which assumes conservative weather assumptions. Therefore, not only can DLR give a more accurate measurement of the true ampacity of a conductor, but it can also increase its ampacity during weather conditions with greater thermal mitigations. The two primary cooling factors in the ampacity calculations are wind speed and direction. In complex terrain, wind speed and direction can have large variations over short distances. Therefore, accurately identifying the limiting span of a transmission line requires high spatial resolution of the wind along its path. One solution is to install dense weather stations along their path, though this can become costly over long distances. Therefore, researchers have investigated the use of Computation Fluid Dynamic (CFD) simulations to accurately compute the wind field along the path of a transmission line and use these results to identify the limiting section of the conductor. This work presents a case study that evaluates the coupling of CFD simulations and forecasted weather simulations using the High-Resolution Rapid Refresh (HRRR) model points over a 2-year span within a region in south eastern Idaho. The primary goal of the work is the evaluation of the number of HRRR model points used, i.e., weather stations, along the path of the line and the accuracy of the resulting ampacity. This was done using 4, 10, 17, 26, and 35 HRRR model points along two transmission line paths. The results indicate that as the number of model points are increased, the DLR ampacity of the lines decrease, yet converge as more points are added and demonstrate little change with additional HRRR points. It is expected that these results can help transmission line operators identify the number of weather stations that must be installed when coupled with CFD simulations and DLR ampacity to ensure accurate ratings and safe operations.

17 WIND ENERGY↗

The Tiny Triplet Finder as a Versatile Track Segment Seeding Engine for Trigger Systems

In high energy physics experiment trigger systems, track segment seeding is a resource consuming function and the primary reason is the computing complexity of the segment finding process. As the Moore's Law is reaching its physical limit, reducing computing complexity should be carefully considered, rather than keep piling up silicon resources. The Tiny Triplet Finder is a scheme that reduces the computing complexity of the segment seeding. As a proof of concept, a 3D track segment seeding engine core based on the Tiny Triplet Finder has been implemented and tested in a low-cost FPGA device. The seeding engine is designed to preselect and group hits (stubs) from detector layers to feed subsequent track fitting stage. The seeding engine consists of a Hough transform space for r-z view and a Tiny Triplet Finder for r-phi view to implement 3D constraints. The seeding engine is organized as a pipeline so that each hit is processed in a single clock cycle. Taking advantage of the register-like storage block scheme which enables effectively resetting of a block RAM within a single clock cycle, clearing or refreshing the seeding engine takes only one clock cycles between two events. The Tiny Triplet Finder is also a generic coincidence finding scheme that can be used for many tasks. As a versatility demonstration, track segment finding performances for two distinctive detector geometries are tested in our seeding engine. In a collider barrel-layer geometry, the fake segment rates are studied for 3D (i.e., both r-phi and r-z views) and 2D (i.e., r-phi or r-z view only) configurations for high hit multiplicity events (>4000 hits/layer in the barrel region). Another detector geometry contains strip plane layers with timing information. The numbers of coincidences, both real or fake, with or without timing ("3D" or "2D") information at various hit multiplicities are studied.

43 PARTICLE ACCELERATORS↗

CMS Token Transition

Within the LHC community, a momentous transition has been occurring in authorization. For nearly 20 years, services within the Worldwide LHC Computing Grid (WLCG) have authorized based on mapping an identity, derived from an X.509 credential, or a group/role, derived from a VOMS extension issued by the experiment. A fundamental shift is occurring to capabilities: the credential, a bearer token, asserts the authorizations of the bearer, not the identity. By the HL-LHC era, the CMS experiment plans for the transition to tokens, based on the WLCG Common JSON Web Token profile, to be complete. Services in the technology architecture include the INDIGO Identity and Access Management server to issue tokens; a HashiCorp Vault server to store and refresh access tokens for users and jobs; a managed token bastion server to push credentials to the HTCondor CredMon service; and HTCondor to maintain valid tokens in long-running batch jobs. We will describe the transition plans of the experiment, current status, configuration of the central authorization server, lessons learned in commissioning token-based access with sites, and operational experience using tokens for both job submissions and file transfers.

43 PARTICLE ACCELERATORS↗

Fermilab's Transition to Token Authentication

Fermilab is the first High Energy Physics institution to transition from X.509 user certificates to authentication tokens in production systems. All the experiments that Fermilab hosts are now using JSON Web Token (JWT) access tokens in their grid jobs. Many software components have been either updated or created for this transition, and most of the software is available to others as open source. The tokens are defined using the WLCG Common JWT Profile. Token attributes for all the tokens are stored in the Fermilab FERRY system which generates the configuration for the CILogon token issuer. High security-value refresh tokens are stored in Hashicorp Vault configured by htvault-config, and JWT access tokens are requested by the htgettoken client through its integration with HTCondor. The Fermilab job submission system jobsub was redesigned to be a lightweight wrapper around HTCondor. The grid workload management system GlideinWMS which is also based on HTCondor was updated to use tokens for pilot job submission. For automated job submissions a managed tokens service was created to reduce duplication of effort and knowledge of how to securely keep tokens active. The existing Fermilab file transfer tool ifdh was updated to work seamlessly with tokens, as well as the Fermilab POMS (Production Operations Management System) which is used to manage automatic job submission and the RCDS (Rapid Code Distribution System) which is used to distribute analysis code via the CernVM FileSystem. The dCache storage system was reconfigured to accept tokens for authentication in place of X.509 proxy certificates. As some services and sites have not yet implemented token support, proxy certificates are still sent with jobs for backwards compatibility, but some experiments are beginning to transition to stop using them.

Dykstra, Dave [Fermilab] (ORCID:0000000326539015)↗

Automated Generation of Graph-based Cyber Threat Intel

With the advancement of AI technology and tools, specifically in the cybersecurity domain, both cyber defenders and threat actors are continuously adapting the use of these capabilities to expedite their operations. With this phenomenon, threat intelligence that is up to date, refreshable, and has relevant context to a specific threat becomes more and more important as it enables cybersecurity professionals to gain insight into relevant data and relationships to guide their operations. This project enables users to frequently aggregate threat intelligence from various sources, such as vendor vulnerability advisories affecting critical infrastructure, malware reports, and adversary writeups into a centralized, standardized database. The project utilizes the Structured Threat Intelligence eXpression (STIX) for a standardized, shareable threat intelligence data format and Neo4j as a graph database solution to store STIX nodes and relationships. Initial results of the project include datasets of over 8,000 nodes and 20,000 relationships extracted from over 500 data sources that have been released within the past month.

Threat Intelligence↗