Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Authentication”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Non-invasive authentication of mail packages using nuclear quadrupole resonance spectroscopy

The international postal network is one of the most widely used methods for correspondence throughout the world. Most postal traffic across the globe consists of legitimate interpersonal, business-consumer, and business-business communications. However, the global postal system is also utilized for criminal activity. In particular, it is often utilized to ship and distribute contraband, including illegal psychoactive drugs such as fentanyl and heroin, to consumers. Existing technological solutions are capable of identifying synthetic opioids and other illegal drugs within packages, but are accompanied by several disadvantages that make them unsuitable for large-scale authentication of international mail traffic. This paper presents a novel method for non-invasive authentication of mail packages that overcomes these challenges. The approach uses nuclear quadrupole resonance (NQR) spectroscopy to detect and quantify the presence of known active pharmaceutical ingredients (APIs) within the package. It has been experimentally demonstrated using a bench top prototype. Test results from a variety of package types demonstrate the effectiveness of the proposed authentication approach.

42 ENGINEERING↗

Digital camera with apparatus for authentication of images produced from an image file

A digital camera equipped with a processor for authentication of images produced from an image file taken by the digital camera is provided. The digital camera processor has embedded therein a private key unique to it, and the camera housing has a public key that is so uniquely based upon the private key that digital data encrypted with the private key by the processor may be decrypted using the public key. The digital camera processor comprises means for calculating a hash of the image file using a predetermined algorithm, and second means for encrypting the image hash with the private key, thereby producing a digital signature. The image file and the digital signature are stored in suitable recording means so they will be available together. Apparatus for authenticating at any time the image file as being free of any alteration uses the public key for decrypting the digital signature, thereby deriving a secure image hash identical to the image hash produced by the digital camera and used to produce the digital signature. The apparatus calculates from the image file an image hash using the same algorithm as before. By comparing this last image hash with the secure image hash, authenticity of the image file is determined if they match, since even one bit change in the image hash will cause the image hash to be totally different from the secure hash.

Friedman, Gary L.↗

Literacity: A multimedia adult literacy package combining NASA technology, recursive ID theory, and authentic instruction theory

An important part of NASA's mission involves the secondary application of its technologies in the public and private sectors. One current application under development is LiteraCity, a simulation-based instructional package for adults who do not have functional reading skills. Using fuzzy logic routines and other technologies developed by NASA's Information Systems Directorate and hypermedia sound, graphics, and animation technologies the project attempts to overcome the limited impact of adult literacy assessment and instruction by involving the adult in an interactive simulation of real-life literacy activities. The project uses a recursive instructional development model and authentic instruction theory. This paper describes one component of a project to design, develop, and produce a series of computer-based, multimedia instructional packages. The packages are being developed for use in adult literacy programs, particularly in correctional education centers. They use the concepts of authentic instruction and authentic assessment to guide development. All the packages to be developed are instructional simulations. The first is a simulation of 'finding a friend a job.'

Willis, Jerry↗

Systems and methods for distributed authentication of devices

A lightweight, fast, and reliable authentication mechanism compatible with the 5G D2D ProSe standard mechanisms is provided. A distributed authentication with a delegation-based scheme avoids repeated access to the 5G core network key management functions. Hence, a legitimate user equipment device (e.g., a drone) is authorized by the cellular network (e.g., 5G cellular network) via offering a proxy signature to authenticate itself to other drones. Test results demonstrate that the protocol is lightweight and reliable.

Akkaya, Kemal↗

Authentication of smart grid communications using quantum key distribution

Smart grid solutions enable utilities and customers to better monitor and control energy use via information and communications technology. Information technology is intended to improve the future electric grid’s reliability, efficiency, and sustainability by implementing advanced monitoring and control systems. However, leveraging modern communications systems also makes the grid vulnerable to cyberattacks. Here we report the first use of quantum key distribution (QKD) keys in the authentication of smart grid communications. In particular, we make such demonstration on a deployed electric utility fiber network. The developed method was prototyped in a software package to manage and utilize cryptographic keys to authenticate machine-to-machine communications used for supervisory control and data acquisition (SCADA). This demonstration showcases the feasibility of using QKD to improve the security of critical infrastructure, including future distributed energy resources (DERs), such as energy storage.

24 POWER TRANSMISSION AND DISTRIBUTION↗

A Novel Authentication Management for the Data Security of Smart Grid

Bidirectional wireless communication is employed in various smart grid components such as smart meters and control and monitoring applications where security is vital. The Trusted Third Party (TTP) and wireless connectivity between the smart meter and the third party in the key management-based encryption techniques for the smart grid are expected to be totally trustworthy and dependable. In a wired/wireless medium, however, a man-in-the-middle may seek to disrupt, monitor and manipulate the network, or simply execute a replay attack, revealing its vulnerability. Recognizing this, this study presents a novel authentication management (model) comprised of two layer security schema. The first layer implements an efficient novel encryption method for secure data exchange between meters and control center with the help of two partially trusted simple servers (constitutes the TTP). In this setting, one server handles the data encryption between the meter and control center/central database, and the other server administers the random sequence of data transmission. The second layer monitors and verifies exchanged data packets among smart meters. It detects abnormal packets from suspicious sources. To implement this node-to-node authentication, One class support vector machine algorithm is proposed which takes advantages of the location information as well as the data transmission history (node identification, packet size, and data transmission frequency). This schema secures data communication, and imposes a comprehensive privacy throughout the system without considerably extending the complexity of the conventional key management scheme.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Active High Assurance Authentication Protocol (AHAAP)

The AHAAP Maturation Project involves maturation and evaluation of a patented zero-trust tamper-resistant high-assurance session-less dynamic and active device authentication protocol that simultaneously authenticates identity and provides integrity verification in a single step, substantially reducing the risk of cyberattack, and eliminating the need for costly and complex conventional communication security systems requirements (i.e., cryptography, Public Key Infrastructure (PKI), and key management). These cybersecurity attributes of the technology must be preserved when applying the technology to different cybersecurity solutions, including Command & Control (C&C), Over-the-Air (OTA) update, Common Access Card (CAC), and distributed energy resource (DER) implementations, among others. The technology research objective is to test and verify that the cybersecurity attributes of the technology are not degraded in different cybersecurity applications. The primary technology development objective is to build minimum viable products to demonstrate the technology addresses today’s cybersecurity threats so that prospective investors, strategic partners, regulatory agencies, and commercial customers can interact with and assess the protection assured by the technology. The AHAAP Maturation Project goal is to develop, test, and validate one or more AHAAP implementations. The AHAAP Maturation Project tasks are: (i) engineer AHAAP implementation software, (ii) build a functional prototype that implements the AHAAP software for demonstration, testing, analysis, and evaluation purposes, and (iii) generate a report detailing the results of the AHAAP C&C software and hardware implementation. The final project deliverables are: (i) AHAAP software implementation and prototype, (ii) a report from Sandia National Laboratories detailing the results of the AHAAP implementations.

97 MATHEMATICS AND COMPUTING↗

Fermilab s Transition to Token Authentication

Fermilab is the first High Energy Physics institution to transition from X.509 user certificates to authentication tokens in production systems. All of the experiments that Fermilab hosts are now using JSON Web Token (JWT) access tokens in their grid jobs. Many software components have been either updated or created for this transition, and most of the software is available to others as open source. The tokens are defined using the WLCG Common JWT Profile. Token attributes for all the tokens are stored in the Fermilab FERRY system which generates the configuration for the CILogon token issuer. High security-value refresh tokens are stored in Hashicorp Vault configured by htvault-config, and JWT access tokens are requested by the htgettoken client through its integration with HTCondor. The Fermilab job submission system jobsub was redesigned to be a lightweight wrapper around HTCondor. For automated job submissions a managed tokens service was created to reduce duplication of effort and knowledge of how to securely keep tokens active. The existing Fermilab file transfer tool ifdh was updated to work seamlessly with tokens, as well as the Fermilab POMS (Production Operations Management System) which is used to manage automatic job submission and the RCDS (Rapid Code Distribution System) which is used to distribute analysis code via the CernVM FileSystem. The dCache storage system was reconfigured to accept tokens for authentication in place of X.509 proxy certificates. As some services and sites have not yet implemented token support, proxy certificates are still sent with jobs for backwards compatibility but some experiments are beginning to transition to stop using them. There have been some glitches and learning curve issues but in general the system has been performing well and is being improved as operational problems are addressed.

Dykstra, David↗

Object migration and authentication

The paper presents a mechanism permitting a type manager to fabricate a migrated object representation which can be entrusted to other subsystems or transmitted outside of the control of a local computer system. The migrated object representation is signed by the type manager in such a way that the type manager's signature cannot be forged and the manager is able to authenticate its own signature. Subsequently, the type manager can retrieve the migrated representation and validate its contents before reconstructing the object in its original representation. This facility allows type managers to authenticate the contents of off-line or network storage and solves problems stemming from the hierarchical structure of the system itself.

Gligor, V. D.↗

Geospatial Authentication

A software package that has been designed to allow authentication for determining if the rover(s) is/are within a set of boundaries or a specific area to access critical geospatial information by using GPS signal structures as a means to authenticate mobile devices into a network wirelessly and in real-time. The advantage lies in that the system only allows those with designated geospatial boundaries or areas into the server.

Lyle, Stacey D.↗

Method and system for identifying and authenticating an object

An object has a taggant placed in a first portion thereof and has a visible symbol placed on a second portion thereof. When the object is to be identified and authenticated, the taggant is made to radiate with a specific energy signature. The energy signature and at least one image of the symbol are recorded along with a relative location that identifies the first portion of the object. The combination of the energy signature, symbol image and relative location are used to repeatedly identify and authenticate the object.

Schramm, Jr., Harry F.↗

Expedition Earth and Beyond: Using Crew Earth Observation Imagery from the International Space Station to Facilitate Student-Led Authentic Research

Student-led authentic research in the classroom helps motivate students in science, technology, engineering, and mathematics (STEM) related subjects. Classrooms benefit from activities that provide rigor, relevance, and a connection to the real world. Those real world connections are enhanced when they involve meaningful connections with NASA resources and scientists. Using the unique platform of the International Space Station (ISS) and Crew Earth Observation (CEO) imagery, the Expedition Earth and Beyond (EEAB) program provides an exciting way to enable classrooms in grades 5-12 to be active participants in NASA exploration, discovery, and the process of science. EEAB was created by the Astromaterials Research and Exploration Science (ARES) Education Program, at the NASA Johnson Space Center. This Earth and planetary science education program has created a framework enabling students to conduct authentic research about Earth and/or planetary comparisons using the captivating CEO images being taken by astronauts onboard the ISS. The CEO payload has been a science payload onboard the ISS since November 2000. ISS crews are trained in scientific observation of geological, oceanographic, environmental, and meteorological phenomena. Scientists on the ground select and periodically update a series of areas to be photographed as part of the CEO science payload.

Graff, P. V.↗

Long-term Engagement in Authentic Research with NASA (LEARN): Innovative Practices Suggested by a New Model for Teacher Research Experiences

NASA's LEARN Project is an innovative program that provides long-term immersion in the practice of atmospheric science for middle and high school in-service teachers. Working alongside NASA scientists and using authentic NASA Science Mission Directorate research data, teachers develop individual research topics of interest during two weeks in the summer while on-site at NASA Langley. With continued, intensive mentoring by NASA scientists, the teachers further develop their research throughout the academic year through virtual group meetings and data team meetings mirroring scientific collaborations. At the end of the first year, LEARN teachers present scientific posters. The LEARN experience has had such an impact that multiple teachers from the first two cohorts have elected to continue their research. The LEARN project evaluation has provided insights into particularly effective elements of this new approach. Findings indicate that teachers? perceptions of the scientific enterprise have changed, and that LEARN provided substantial resources to help them take real-world research to their students. This presentation will focus on key factors from LEARN?s implementation that inform best practices for the incorporation of authentic scientific research into teacher professional development experiences. We suggest that these factors should be considered in the development of other such experiences, including: (1) The involvement of a single scientist as both the project leader/manager and the project scientist, to ensure that the project can meet teachers? needs. (2) An emphasis on framing and approaching scientific research questions, so that teachers can learn to evaluate the feasibility of studies based on scope, scale, and availability of data. (3) Long term, ongoing relationships where teachers and scientists work as collaborators, beyond the workshop ?mold.? (4) A focus on meeting the needs of individual teachers, whether their needs relate to elements of research and analysis, or to their tight professional schedules. (5) Above all, flexibility and patience. LEARN builds relationships with teachers slowly, over a long period of time. In the middle, life often intervenes. LEARN has emphasized that teachers? success is more important than deadlines or following a rigid protocol.

M Pippin↗

Systems and methods for quantum optical device authentication

Quantum optical device authentication technologies are described herein. A first device includes an optical transmitter transmits a plurality of pulses to an optical receiver included on a second device. The optical pulses each have one of two non-orthogonal optical states. The optical receiver measures each of the pulses and the second device records a measured value of the optical state of each pulse. Subsequently, the second device transmits the measured values of the optical states of the pulses to the first device. The first device outputs an indication of whether the second device is authenticated based upon the measured values received from the second device and the optical states of the pulses transmitted by the optical transmitter.

Soh, Daniel Beom Soo↗

Secure authentication using recurrent neural networks

A computer-implemented method of user authentication is provided. The method comprises combining, by a computer system, a user recurrent neural network with a system recurrent neural network to form a unique combined recurrent neural network. The user recurrent neural network is configured to generate a unique user key, and the system recurrent neural network is configured to generate a system key. The computer system inputs a predetermined input into the combined recurrent neural network, and the combined recurrent neural network generates a unique combined key from the input, wherein the combined key differs from both the user key and system key. The computer system then associates the combined key with a unique access authorization to authenticate a user.

Aimone, James Bradley↗

Methods and systems for authenticating identity

Systems and methods are disclosed that provide for secure communications between a user device and an authentication system. The systems and methods create a dynamic identification for the device that is stored in both the device and authentication system.

Choi, Sung Nam↗

Systems, devices, and methods for authenticating millimeter wave devices

Systems, devices, and methods are described for millimeter wave device authentication. A system may include one or more access points. Each access point of the one or more access points is configured to extract, from one or more beam patterns generated via a client device, a beam feature associated with the client device. Each access point may also be configured to transmit the beam feature. The system may also include a server communicatively coupled to the one or more access points and including a database for storing known beam features. The server may be configured to receive the beam feature associated with the client device from at least one access point of the one or more access points. Also, the server may be configured to authenticate the client device in response to the received beam feature matching a known beam feature stored in the at least one database.

Bhuyan, Arupjyoti↗

Fermilab's Transition to Token Authentication

Fermilab is the first High Energy Physics institution to transition from X.509 user certificates to authentication tokens in production systems. All the experiments that Fermilab hosts are now using JSON Web Token (JWT) access tokens in their grid jobs. Many software components have been either updated or created for this transition, and most of the software is available to others as open source. The tokens are defined using the WLCG Common JWT Profile. Token attributes for all the tokens are stored in the Fermilab FERRY system which generates the configuration for the CILogon token issuer. High security-value refresh tokens are stored in Hashicorp Vault configured by htvault-config, and JWT access tokens are requested by the htgettoken client through its integration with HTCondor. The Fermilab job submission system jobsub was redesigned to be a lightweight wrapper around HTCondor. The grid workload management system GlideinWMS which is also based on HTCondor was updated to use tokens for pilot job submission. For automated job submissions a managed tokens service was created to reduce duplication of effort and knowledge of how to securely keep tokens active. The existing Fermilab file transfer tool ifdh was updated to work seamlessly with tokens, as well as the Fermilab POMS (Production Operations Management System) which is used to manage automatic job submission and the RCDS (Rapid Code Distribution System) which is used to distribute analysis code via the CernVM FileSystem. The dCache storage system was reconfigured to accept tokens for authentication in place of X.509 proxy certificates. As some services and sites have not yet implemented token support, proxy certificates are still sent with jobs for backwards compatibility, but some experiments are beginning to transition to stop using them.

Dykstra, Dave [Fermilab] (ORCID:0000000326539015)↗