Engineering PapersSearch

SEARCH · Engineering Papers

Results for “secure communications”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Framework for Flexible Security in Group Communications

The Antigone software system defines a framework for the flexible definition and implementation of security policies in group communication systems. Antigone does not dictate the available security policies, but provides high-level mechanisms for implementing them. A central element of the Antigone architecture is a suite of such mechanisms comprising micro-protocols that provide the basic services needed by secure groups.

McDaniel, Patrick

How Autonomous Intelligent Systems Can Facilitate Earth-independent Medical Care: Going Beyond Telepresence

During the last decade, teleoperated robotic systems have extended humans’ sensorimotor competence to digitally fly beyond the physical barrier of distance and scale and thus transmit sensorimotor skills of the human through direct communication. Telepresence capabilities have enabled tele-physical remote access at small scales thanks to telerobotic mediums. Although the concept was initially motivated by space applications, such technologies quickly have expanded into the medical domain and resulted in teleoperated medical robots, including telerobotic surgical systems (such as the da Vinci surgical system). Effective telepresence fundamentally depends on an agile, reliable, and secure communication medium that can transmit real-time information between the operator and a remote device. However, direct telepresence may not be achievable for long-duration exploration spaceflight missions. Thus, autonomous systems and local intelligence represent potential solutions to the aforementioned issues. One example solution employs demonstration systems which enable learning from the pre-captured inputs of a skilled human operator. These will be computationally modeled and later probabilistically replicated toward the completion of remote physical tasks when direct telepresence is not viable - such as under communication blackout conditions. In other words, trained autonomous systems (e.g., robots) can perform remote operations that mimic the physical performance of experts during remote operations/training. Beyond learning the physics of the task, autonomous agents can also be used to conduct algorithmic decision-making that mimics the higher-level cognition of the expert. Thus, using an autonomous system, pre-trained cognitive and manipulation-based skills can be leveraged (acquired during pre-mission events) to produce digital twins of an intelligent operator. Such systems can be used for the real-time conduction of intricate tasks in complex and unstructured environments. Such systems will operationalize “cognitive digital twins” and can expand the reach of human cognition and manipulation through the power of data-driven learning from demonstration algorithms. This system category will be discussed as a fully autonomous operation in this talk. In addition to the above, we will also propose and discuss the possibility of partial-automation using remote intelligence and remote sensing. In contrast to full automation, partial automation can close the loop through a local operator equipped with augmented sensory awareness through wearable systems. Such technologies will allow the local operator to conduct delicate tasks while being guided using sensory augmentation and being monitored to gauge her/his level of cognitive focus and performance. The difference with the previous category is that a remote human will conduct the task. Further, rather than making a digital twin of human cognition, we will augment the control inputs of the local human to match those of the skilled expert operator who is not accessible in real-time. Going beyond classic telepresence and thus approaching intelligent telepresence, our vision is that autonomous agents will eventually enable the safe, consistent and efficient delivery of complex, remote and smart medical care during space exploration across operators in an Earth-independent fashion. We will discuss our collective vision from NASA and MERIIT@NYU lab in this talk.

Telepresence

Study terrestrial applications of solar cell powered systems

Terrestrial applications of solar cells and design systems are considered for those applications that show the most promise for becoming practical and accepted by users within the next five years. The study includes the definition, categorization, evaluation and screening of the most attractive potential terrestrial applications for solar cells. Potential markets are initially grouped and categorized in a general sense and are weighted in priority by their business volume, present and future. From a categorized list including marine, transportation, security, communication, meteorological and others, 66 potential solar cell applications have been cataloged. A methodology was formulated to include the criteria for evaluation and screening. The evaluation process covers all parts and components of the complete system required for each application and gives consideration to all factors, such as engineering, economic, production, marketing and other factors that may have an influence on the acceptance of the system.

Ravin, J. W.

Access control and privacy in large distributed systems

Large scale distributed systems consists of workstations, mainframe computers, supercomputers and other types of servers, all connected by a computer network. These systems are being used in a variety of applications including the support of collaborative scientific research. In such an environment, issues of access control and privacy arise. Access control is required for several reasons, including the protection of sensitive resources and cost control. Privacy is also required for similar reasons, including the protection of a researcher's proprietary results. A possible architecture for integrating available computer and communications security technologies into a system that meet these requirements is described. This architecture is meant as a starting point for discussion, rather that the final answer.

Leiner, B. M.

Access control and privacy in large distributed systems

Large scale distributed systems consists of workstations, mainframe computers, supercomputers and other types of servers, all connected by a computer network. These systems are being used in a variety of applications including the support of collaborative scientific research. In such an environment, issues of access control and privacy arise. Access control is required for several reasons, including the protection of sensitive resources and cost control. Privacy is also required for similar reasons, including the protection of a researcher's proprietary results. A possible architecture for integrating available computer and communications security technologies into a system that meet these requirements is described. This architecture is meant as a starting point for discussion, rather that the final answer.

Leiner, B. M.

Transportation Network Topologies

The existing U.S. hub-and-spoke air transportation system is reaching saturation. Major aspects of the current system, such as capacity, safety, mobility, customer satisfaction, security, communications, and ecological effects, require improvements. The changing dynamics - increased presence of general aviation, unmanned autonomous vehicles, military aircraft in civil airspace as part of homeland defense - contributes to growing complexity of airspace. The system has proven remarkably resistant to change. NASA Langley Research Center and the National Institute of Aerospace conducted a workshop on Transportation Network Topologies on 9-10 December 2003 in Williamsburg, Virginia. The workshop aimed to examine the feasibility of traditional methods for complex system analysis and design as well as potential novel alternatives in application to transportation systems, identify state-of-the-art models and methods, conduct gap analysis, and thus to lay a foundation for establishing a focused research program in complex systems applied to air transportation.

Alexandrov, Natalia

IT Challenges for Space Medicine or How do We Protect Medical Information and Still Get Useful Work Done?

Space Medicine provides healthcare services of various types for astronauts throughout their lifetime starting from the time they are selected as astronauts. IT challenges include: protection of private medical information, access from locations both inside and outside NASA, nearly 24x7 access, access during disasters, international partner access, data archiving, off-region backup, secure communication of medical data to people outside the NASA system (e.g. expert consultants), efficient movement of medical record information between locations, search and retrieval of relevant information, and providing all of these services/capabilities within a limited budget. In Space Medicine, we have provided for these in various ways: limit the amount of private medical information stored locally, utilize encryption mechanisms that the international partners can also use, utilize 2-factor authentication, virtualize servers, employ concept-based search, and use of standardized terminologies (SNOMED) and messaging (HL7).

Johnson-Throop, Kathy A.

Free-Space Quantum Key Distribution with a High Generation Rate Potassium Titanyl Phosphate Waveguide Photon-Pair Source

A high generation rate photon-pair source using a dual element periodically-poled potassium titanyl phosphate (PP KTP) waveguide is described. The fully integrated photon-pair source consists of a 1064-nanometer pump diode laser, fiber-coupled to a dual element waveguide within which a pair of 1064-nanometer photons are up-converted to a single 532-nanometer photon in the first stage. In the second stage, the 532-nanometer photon is down-converted to an entangled photon-pair at 800 nanometer and 1600 nanometer which are fiber-coupled at the waveguide output. The photon-pair source features a high pair generation rate, a compact power-efficient package, and continuous wave (CW) or pulsed operation. This is a significant step towards the long term goal of developing sources for high-rate Quantum Key Distribution (QKD) to enable Earth-space secure communications. Characterization and test results are presented. Details and preliminary results of a laboratory free-space QKD experiment with the B92 protocol are also presented.

photons

Reliable, Secure, and Scalable Communications, Navigation, and Surveillance (CNS) Options for Urban Air Mobility (UAM)

The Aeronautics Research Mission Directorate directed a study to identify, evaluate, and recommend viable communications, navigation, and surveillance systems and technologies to enable safe, secure, and efficient Urban Air Mobility operations in US cities. The focus is on UML-4, when commercial air taxi operations take place in all weather, are widespread, and include autonomous systems. This report recommends technologies for independent navigation, collaborative communication, and surveillance, based on capacity, availability, precision, and update rate, size, weight, power, cost and other values. Recommendations for maturing and implementing the technologies are included.

Virginia L. Stouffer

A Security Model for Space Based Communication

This viewgraph presentation reviews the security requirements for space based communications and the tools which can be used in the design of space based communications systems.

Stone, Thom

Ensuring Flexibility and Security in SDN-Based Spacecraft Communication Networks Through Risk Assessment

Software-defined networking (SDN) has enabled elastic networking and resource distribution in cloud computing. The centralization and separation of the Control Plane also offers a high degree of network configurability and management, which can be used to mitigate and manage threats to the network. Space communication networks have historically been restricted and circuit switching in these networks has been a manual process. This study evaluates the potential role of SDN in space communication networks from a networking security standpoint. The evaluation covers the networking security needs of spacecraft missions and their associated assets. The results from the evaluation lead to a risk assessment that identifies vulnerabilities in an SDN-based communications architecture. Security challenges introduced into the network from integrating SDN are also considered. A risk register summarizes the severity of the attack outcomes, as well as occurrence likelihood. The study identifies Denial-of-Service (DoS) attacks as a new threat (presently unmitigated by existing security controls) that would be prevalent in an SDN-based space communication environment. A Mininet-based emulation testbed is built to demonstrate the susceptibility of spacecraft flight software to a flooding DoS attack when on an interconnected SDN-managed network. This type of attack would be highly consequential to mission assets, and therefore SDN-based space communications would need to be resilient to such attacks. Future work will need to be performed to fully characterize DoS attack methods that can apply to the space communication scenario, as well as to devise a comprehensive DoS-resilient solution.

Baker, Dylan Z.

Securing and Auto-Synchronizing Communication over Free-Space Optics Using Quantum Key Distribution and Chaotic Systems

Free-Space Optical (FSO) communication provides very large bandwidth, relatively low cost, low power, low mass of implementation, and improved security when compared to conventional Free-Space Radio-Frequency (FSRF) systems. In this paper, we demonstrate a communication protocol that demonstrates improved security and longer-range FSO communication, compared to existing FSO security techniques, such as N-slit interferometers. The protocol integrates chaotic communications with Quantum Key Distribution (QKD) techniques. A Lorenz chaotic system, which is inherently secure and auto-synchronized, is utilized for secure data communications over a classical channel, while QKD is used to exchange crucial chaotic system parameters over a secure quantum channel. We also provide a concept of operations for a NASA mission combining chaotic communications and QKD operating synergistically in an end-to-end space communications link. The experimental simulation results and analysis are favorable towards our approach.

Chaotic Communication

Monte Carlo simulations of precise timekeeping in the Milstar communication satellite system

The Milstar communications satellite system will provide secure antijam communication capabilities for DOD operations into the next century. In order to accomplish this task, the Milstar system will employ precise timekeeping on its satellites and at its ground control stations. The constellation will consist of four satellites in geosynchronous orbit, each carrying a set of four rubidium (Rb) atomic clocks. Several times a day, during normal operation, the Mission Control Element (MCE) will collect timing information from the constellation, and after several days use this information to update the time and frequency of the satellite clocks. The MCE will maintain precise time with a cesium (Cs) atomic clock, synchronized to UTC(USNO) via a GPS receiver. We have developed a Monte Carlo simulation of Milstar's space segment timekeeping. The simulation includes the effects of: uplink/downlink time transfer noise; satellite crosslink time transfer noise; satellite diurnal temperature variations; satellite and ground station atomic clock noise; and also quantization limits regarding satellite time and frequency corrections. The Monte Carlo simulation capability has proven to be an invaluable tool in assessing the performance characteristics of various timekeeping algorithms proposed for Milstar, and also in highlighting the timekeeping capabilities of the system. Here, we provide a brief overview of the basic Milstar timekeeping architecture as it is presently envisioned. We then describe the Monte Carlo simulation of space segment timekeeping, and provide examples of the simulation's efficacy in resolving timekeeping issues.

Camparo, James C.

Toward Synthesis, Analysis, and Certification of Security Protocols

Implemented security protocols are basically pieces of software which are used to (a) authenticate the other communication partners, (b) establish a secure communication channel between them (using insecure communication media), and (c) transfer data between the communication partners in such a way that these data only available to the desired receiver, but not to anyone else. Such an implementation usually consists of the following components: the protocol-engine, which controls in which sequence the messages of the protocol are sent over the network, and which controls the assembly/disassembly and processing (e.g., decryption) of the data. the cryptographic routines to actually encrypt or decrypt the data (using given keys), and t,he interface to the operating system and to the application. For a correct working of such a security protocol, all of these components must work flawlessly. Many formal-methods based techniques for the analysis of a security protocols have been developed. They range from using specific logics (e.g.: BAN-logic [4], or higher order logics [12] to model checking [2] approaches. In each approach, the analysis tries to prove that no (or at least not a modeled intruder) can get access to secret data. Otherwise, a scenario illustrating the &tack may be produced. Despite the seeming simplicity of security protocols ("only" a few messages are sent between the protocol partners in order to ensure a secure communication), many flaws have been detected. Unfortunately, even a perfect protocol engine does not guarantee flawless working of a security protocol, as incidents show. Many break-ins and security vulnerabilities are caused by exploiting errors in the implementation of the protocol engine or the underlying operating system. Attacks using buffer-overflows are a very common class of such attacks. Errors in the implementation of exception or error handling can open up additional vulnerabilities. For example, on a website with a log-in screen: multiple tries with invalid passwords caused the expected error message (too many retries). but let the user nevertheless pass. Finally, security can be compromised by silly implementation bugs or design decisions. In a commercial VPN software, all calls to the encryption routines were incidentally replaced by stubs, probably during factory testing. The product worked nicely. and the error (an open VPN) would have gone undetected, if a team member had not inspected the low-level traffic out of curiosity. Also, the use secret proprietary encryption routines can backfire, because such algorithms often exhibit weaknesses which can be exploited easily (see e.g., DVD encoding). Summarizing, there is large number of possibilities to make errors which can compromise the security of a protocol. In today s world with short time-to-market and the use of security protocols in open and hostile networks for safety-critical applications (e.g., power or air-traffic control), such slips could lead to catastrophic situations. Thus, formal methods and automatic reasoning techniques should not be used just for the formal proof of absence of an attack, but they ought to be used to provide an end-to-end tool-supported framework for security software. With such an approach all required artifacts (code, documentation, test cases) , formal analyses, and reliable certification will be generated automatically, given a single, high level specification. By a combination of program synthesis, formal protocol analysis, certification; and proof-carrying code, this goal is within practical reach, since all the important technologies for such an approach actually exist and only need to be assembled in the right way.

Schumann, Johann

Wide-Band, High-Quantum-Efficiency Photodetector

A design has been proposed for a photodetector that would exhibit a high quantum efficiency (as much as 90 percent) over a wide wavelength band, which would typically be centered at a wavelength of 1.55 m. This and similar photodetectors would afford a capability for detecting single photons - a capability that is needed for research in quantum optics as well as for the practical development of secure optical communication systems for distribution of quantum cryptographic keys. The proposed photodetector would be of the hot-electron, phonon-cooled, thin-film superconductor type. The superconducting film in this device would be a meandering strip of niobium nitride. In the proposed photodetector, the quantum efficiency would be increased through incorporation of optiA design has been proposed for a photodetector that would exhibit a high quantum efficiency (as much as 90 percent) over a wide wavelength band, which would typically be centered at a wavelength of 1.55 m. This and similar photodetectors would afford a capability for detecting single photons - a capability that is needed for research in quantum optics as well as for the practical development of secure optical communication systems for distribution of quantum cryptographic keys. The proposed photodetector would be of the hot-electron, phonon-cooled, thin-film superconductor type. The superconducting film in this device would be a meandering strip of niobium nitride. In the proposed photodetector, the quantum efficiency would be increased through incorporation of opti-

Jackson, Deborah

Secure Intra-Body Wireless Communications (SIWiC) System Project

SIWiC System is a project to investigate, design and implement future wireless networks of implantable sensors in the body. This futuristic project is designed to make use of the emerging and yet-to-emerge technologies, including ultra-wide band (UWB) for wireless communications, smart implantable sensors, ultra low power networking protocols, security and privacy for bandwidth and power deficient devices and quantum computing. Progress in each of these fronts is hindered by the needs of breakthrough. But, as we will see in this paper, these major challenges are being met or will be met in near future. SIWiC system is a network of in-situ wireless devices that are implanted to coordinate sensed data inside the body, such as symptoms monitoring collected internally, or biometric data collected of an outside object from within the intra-body network. One node has the capability of communicating outside the body to send data or alarm to a relevant authority, e.g., a remote physician.

Ahmad, Aftab