Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “source authentication”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

A Novel Authentication Management for the Data Security of Smart Grid

Bidirectional wireless communication is employed in various smart grid components such as smart meters and control and monitoring applications where security is vital. The Trusted Third Party (TTP) and wireless connectivity between the smart meter and the third party in the key management-based encryption techniques for the smart grid are expected to be totally trustworthy and dependable. In a wired/wireless medium, however, a man-in-the-middle may seek to disrupt, monitor and manipulate the network, or simply execute a replay attack, revealing its vulnerability. Recognizing this, this study presents a novel authentication management (model) comprised of two layer security schema. The first layer implements an efficient novel encryption method for secure data exchange between meters and control center with the help of two partially trusted simple servers (constitutes the TTP). In this setting, one server handles the data encryption between the meter and control center/central database, and the other server administers the random sequence of data transmission. The second layer monitors and verifies exchanged data packets among smart meters. It detects abnormal packets from suspicious sources. To implement this node-to-node authentication, One class support vector machine algorithm is proposed which takes advantages of the location information as well as the data transmission history (node identification, packet size, and data transmission frequency). This schema secures data communication, and imposes a comprehensive privacy throughout the system without considerably extending the complexity of the conventional key management scheme.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Advancing Open Science in Atmospheric Research: Integrating Data Usability and Machine Learning

In the dynamic realm of atmospheric sciences, the convergence of data science methodologies and open data marks a transformative era, driving research advancements and nurturing aspiring scientists. This abstract highlights two pivotal projects that epitomize open science principles, aligning seamlessly with the session's objective of interdisciplinary synergy and the cultivation of emerging talent. As a NASA-certified data center, our foremost endeavor focuses on enhancing the visibility and traceability of NASA datasets within atmospheric science research. This initiative not only elevates these datasets' prominence but also establishes a robust framework ensuring their credibility in scholarly discourse. By bridging the gap between data sources and research publications, this project serves as an educational catalyst, nurturing a new generation of scholars in open collaboration and dataset authenticity. Concurrently, our second project pioneers an early warning system for flooding events, utilizing machine learning algorithms to predict flooded fractions. Through multi-source data fusion and predictive modeling, this initiative goes beyond forecasting; it embodies the core of open science by enabling proactive risk mitigation strategies. This project not only advances atmospheric sciences but also fosters an environment where young scholars engage in practical, data-driven solutions. These intertwined projects exemplify the fusion of data science with open data solutions, ensuring both the usability of quality datasets and the cultivation of scientific knowledge among emerging scholars. By spotlighting these impactful use cases, our aim is to foster discussions emphasizing the importance of open collaboration, data integrity, and the nurturing of scientific talent in atmospheric sciences." "In the dynamic realm of atmospheric sciences, the convergence of data science methodologies and open data marks a transformative era, driving research advancements and nurturing aspiring scientists. This abstract highlights two pivotal projects that epitomize open science principles, aligning seamlessly with the session's objective of interdisciplinary synergy and the cultivation of emerging talent. As a NASA-certified data center, our foremost endeavor focuses on enhancing the visibility and traceability of NASA datasets within atmospheric science research. This initiative not only elevates these datasets' prominence but also establishes a robust framework ensuring their credibility in scholarly discourse. By bridging the gap between data sources and research publications, this project serves as an educational catalyst, nurturing a new generation of scholars in open collaboration and dataset authenticity. Concurrently, our second project pioneers an early warning system for flooding events, utilizing machine learning algorithms to predict flooded fractions. Through multi-source data fusion and predictive modeling, this initiative goes beyond forecasting; it embodies the core of open science by enabling proactive risk mitigation strategies. This project not only advances atmospheric sciences but also fosters an environment where young scholars engage in practical, data-driven solutions. These intertwined projects exemplify the fusion of data science with open data solutions, ensuring both the usability of quality datasets and the cultivation of scientific knowledge among emerging scholars. By spotlighting these impactful use cases, our aim is to foster discussions emphasizing the importance of open collaboration, data integrity, and the nurturing of scientific talent in atmospheric sciences.

Jennifer Wei↗

TACPLUS-DO-AUTH

SF-23-084 This software provides enhanced authorization and access control support to be used in tandem with the open source Terminal Access Controller Access Control System (TACACS+) software tac_plus; providing Authentication, Authorization and Auditing (AAA) capabilities for networking devices.

WEST, GABRIALA↗

The State of CryptoLib – The Open-Source Satellite Cryptography Library

What state would the world be in if all internet traffic was unencrypted? Imagine an alternate universe where you can plug a packet sniffing device into your home internet and capture the web traffic of the entire world. It seems obvious that this scenario is less than desirable. If we would not allow this for the internet, why would we allow this in the space domain? With the advent of open-source ground stations, commercial off the shelf hardware, and ground stations as a service, the barrier to entry for space communications is rapidly lowering. New players enter the space realm everydayevery day, and the presence of tools to allow apprentice evildoers the ability to exploit satellite communications is on the horizon. Not only are legacy missions at risk, but future missions are as well - particularly lower budget science missions with more stringent sciencesize, weight, and power constraints. that may find it difficult to utilize hardware-based encryption solutions. In terms of Civilian Aerospace, NASA Standard 1006 generally directs that missions "shall protect the command stack with encryption that meets or exceeds Federal Information Processing Standards (FIPS) 140". Fortunately, the Consultative Committee for Space Data Systems (CCSDS) has published an international standard on Space Data Link Security. The combination of these two forces has resulted in CryptoLib - an open-source, C-based, encryption library that aims to be CCSDS SDLS compliant. CryptoLib is designed to support smaller missions on a tight budget that may be subject to the more stringent command link encryption requirements. Additionally, CryptoLib serves as an underpinning in JPL's Key Management & Cryptography (KMC) suite and is also designed to function as a 'drop-in' for smaller missions. CryptoLib is in active development and currently provides Telecommand (TC), Telemetry (TM), and Advanced Orbiting Systems (AOS) encryption and decryption capabilities with a variety of encryption and authentication schemes. This presentation will report the latest features, current status, and future plans for CryptoLib.

open-source encryption↗

The State of Cryptolib – The Open-Source Satellite Cryptography Library

What state would the world be in if all internet traffic was unencrypted? Imagine an alternate universe where you can plug a packet sniffing device into your home internet and capture the web traffic of the entire world. It seems obvious that this scenario is less than desirable. If we would not allow this for the internet, why would we allow this in the space domain? With the advent of open-source ground stations, commercial off the shelf hardware, and ground stations as a service, the barrier to entry for space communications is rapidly lowering. New players enter the space realm everydayevery day, and the presence of tools to allow apprentice evildoers the ability to exploit satellite communications is on the horizon. Not only are legacy missions at risk, but future missions are as well - particularly lower budget science missions with more stringent sciencesize, weight, and power constraints. that may find it difficult to utilize hardware-based encryption solutions. In terms of Civilian Aerospace, NASA Standard 1006 generally directs that missions "shall protect the command stack with encryption that meets or exceeds Federal Information Processing Standards (FIPS) 140". Fortunately, the Consultative Committee for Space Data Systems (CCSDS) has published an international standard on Space Data Link Security. The combination of these two forces has resulted in CryptoLib - an open-source, C-based, encryption library that aims to be CCSDS SDLS compliant. CryptoLib is designed to support smaller missions on a tight budget that may be subject to the more stringent command link encryption requirements. Additionally, CryptoLib serves as an underpinning in JPL's Key Management & Cryptography (KMC) suite and is also designed to function as a 'drop-in' for smaller missions. CryptoLib is in active development and currently provides Telecommand (TC), Telemetry (TM), and Advanced Orbiting Systems (AOS) encryption and decryption capabilities with a variety of encryption and authentication schemes. This presentation will report the latest features, current status, and future plans for CryptoLib.

open-source encryption↗

Surface Processes Control the Fate of Reactive Oxidants Generated by Electrochemical Activation of Hydrogen Peroxide on Stainless-Steel Electrodes

Low-cost stainless-steel electrodes can activate hydrogen peroxide (H 2 O 2 ) by converting it into a hydroxyl radical ( • OH) and other reactive oxidants. At an applied potential of +0.020 V, the stainless-steel electrode produced • OH with a yield that was over an order of magnitude higher than that reported for other systems that employ iron oxides as catalysts under circumneutral pH conditions. Decreasing the applied potential at pH 8 and 9 enhanced the rate of H 2 O 2 loss by shifting the process to a reaction mechanism that resulted in the formation of an Fe(IV) species. Significant metal leaching was only observed under acidic pH conditions (i.e., at pH <6), with the release of dissolved Fe and Cr occurring as the thickness of the passivation layer decreased. Despite the relatively high yield of • OH production under circumneutral pH conditions, most of the oxidants were scavenged by the electrode surface when contaminant concentrations comparable to those expected in drinking water sources were tested. The stainless-steel electrode efficiently removed trace organic contaminants from an authentic surface water sample without contaminating the water with Fe and Cr. With further development, stainless-steel electrodes could provide a cost-effective alternative to other H 2 O 2 activation processes, such as those by ultraviolet light.

42 ENGINEERING↗

Finding a needle in a haystack: quantitative HERFD-XRF imaging and HERFD-XANES characterization of trace platinum in gold solidi from the Late Roman and Byzantine Empires

High-Energy Resolution Fluorescence Detection X-Ray Fluorescence (HERFD-XRF) imaging and HERFD X-ray Absorption Near Edge Structure (XANES) spectroscopy are used to quantify and characterize trace platinum (Pt) in gold solidi from the Late Roman and Byzantine Empires. Historically, the elemental analysis of coins has been pivotal in distinguishing authentic artifacts from forgeries, elucidating minting practices, and understanding economic shifts. Notably, a new gold source with high platinum content appeared in the fourth century CE, transforming the Roman economy. Traditional methods struggled to detect platinum due to the overwhelming gold matrix. Here, this study demonstrates the effectiveness of HERFD techniques in resolving this challenge. Three gold solidi, minted between 654 and 659 CE, were analyzed alongside reference gold materials with known Pt concentrations. The HERFD-XRF imaging revealed spatial distributions of platinum, highlighting non-uniformities within the coins. Additionally, HERFD-XANES spectroscopy identified the oxidation states and chemical speciation of platinum. Results demonstrate that platinum in the solidi primarily exists as metallic Pt, with some surface oxidation. The findings align with previous measurements but reveal higher Pt concentrations and significant inhomogeneities. This research confirms the reliability of HERFD methods for quantifying trace elements and provides new insights into the raw material sources and minting techniques of ancient gold coins. The non-destructive nature of this approach allows for extensive analyses, offering valuable data for historical, economic, and archaeological studies. This innovative application of HERFD-XRF imaging and XANES in cultural heritage research underscores the potential for detailed material characterization and conservation, enhancing our understanding of ancient economies and trade patterns.

Van Loon, Lisa L.↗

HERMA-Heartbeat Microwave Authentication

Systems and methods for identifying and/or authenticating individuals utilizing microwave sensing modules are disclosed. A HEaRtbeat Microwave Authentication (HERMA) system can enable the active identification and/or authentication of a user by analyzing reflected RF signals that contain a person's unique characteristics related to their heartbeats. An illumination signal is transmitted towards a person where a reflected signal captures the motion of the skin and tissue (i.e. displacement) due to the person's heartbeats. The HERMA system can utilize existing transmitters in a mobile device (e.g. Wi-Fi, Bluetooth, Cellphone signals) as the illumination source with at least one external receive antenna. The received reflected signals can be pre-processed and analyzed to identify and/or authenticate a user.

Lux, James Paul↗

The LCLStream Ecosystem for Multi-Institutional Dataset Exploration

We describe a new end-to-end experimental data streaming framework designed from the ground up to support new types of applications – AI training, extremely high-rate X-ray time-of-flight analysis, crystal structure determination with distributed processing, and custom data science applications and visualizers yet to be created. Throughout, we use design choices merging cloud microservices with traditional HPC batch execution models for security and flexibility. This project makes a unique contribution to the DOE Integrated Research Infrastructure (IRI) landscape. By creating a flexible, API-driven data request service, we address a significant need for high-speed data streaming sources for the X-ray science data analysis community. With the combination of data request API, mutual authentication web security framework, job queue system, high-rate data buffer, and complementary nature to facility infrastructure, the LCLStreamer framework has prototyped and implemented several new paradigms critical for future generation experiments.

Rogers, David [ORNL] (ORCID:0000000251871768)↗

Ruby on Rails Applications

Ruby on Rails is an open source web application framework for the Ruby programming language. The first application I built was a web application to manage and authenticate other applications. One of the main requirements for this application was a single sign-on service. This allowed authentication to be built in one location and be implemented in many different applications. For example, users would be able to login using their existing credentials, and be able to access other NASA applications without authenticating again. The second application I worked on was an internal qualification plan app. Previously, the viewing of employee qualifications was managed through Excel spread sheets. I built a database driven application to streamline the process of managing qualifications. Employees would be able to login securely to view, edit and update their personal qualifications.

Hochstadt, Jake↗

UCB-GLOBES: An open-access mass spectral database of identified and unidentified atmospheric organic compounds

Chemical characterization of atmospheric organic aerosols using gas chromatography with 70 eV electron ionization mass spectrometry (GC/EI-MS) has been used for decades in advancing molecular marker detection and identification, though primarily through suspect screening and/or targeted analyses. To advance non-targeted analyses of environmental samples, we have catalogued approximately 27 000 mass spectra (MS) of the trimethylsilyl derivatives of semi-volatile organic aerosol (OA) analytes in the open-access University of California Berkeley Goldstein Library of Organic Biogenic Environmental Spectra (UCB-GLOBES). Analytes were observed in ambient samples from the U.S. and the Central Amazon and/or laboratory simulations of secondary OA (SOA) formation. These samples are representative of OA under urban and biomass burning influences as well as SOA derived from biogenic precursors (e.g., isoprene, monoterpenes, sesquiterpenes) and biomass burning intermediates. MS are documented in UCB-GLOBES without regard to known chemical identity, annotated with extensive metadata such as sample source/experimental conditions, any structural information gained from MS analyses, and predicted chemical properties such as average carbon oxidation state and carbon number. UCB-GLOBES MS are compatible for importing into the NIST MS Search program, and we have also provided a Jupyter Notebook for MS visualization and comparisons. We demonstrate the utility of UCB-GLOBES through MS reanalyses of prior analytes observed in ambient data, finding a 20 % reduction in the number of analytes assigned to OA source categories reliant solely on time series correlation and an overall 11 % increase in new MS-based OA source categorization for the Southeast U.S. For 1513 analytes observed previously in the Central Amazon, we found 375 MS matches using UCB-GLOBES vs. 136 MS matches during prior analyses, representing a 14 % gain in newly confirmed or newly categorized OA species. While OA from laboratory oxidation experiments in UCB-GLOBES are highly diverse chemically, on average only 29 % of UCB-GLOBES MS have a mass spectral match to another MS entry in UCB-GLOBES and/or in databases of known compounds (i.e. NIST MS Database, Adams Essential Oil, MANE Flavor and Fragrance Company). This indicates that roughly 70 % of UCB-GLOBES MS are unique thus far, not observed more than once among the laboratory oxidation samples and ambient data in UCB-GLOBES MS. Further, only 18 % can be positively identified using these databases or known authentic standards. This points to a large gap between these laboratory simulations and ambient OA. Overall, the UCB-GLOBES database can be utilized for improving confidence in OA source categorization and/or identification, novel chemical marker discovery, tracking chemical diversity, de novo structure and properties prediction, and improving MS search and matching algorithms. This can ultimately inform future research priorities for the chemical characterization of atmospheric organic samples.

Mass spectrometry↗

Investigating Secondary Aerosol Processes in the Amazon through Molecular-level Characterization of Semi-Volatile Organics

In areas where biogenic emissions are oxidized in the presence of anthropogenic pollutants, it has become increasingly apparent that secondary organic aerosol (SOA) formation from biogenic volatile organic compounds (BVOCs) is substantially enhanced. The Amazon forest is the dominant source of BVOCs globally, and the forest is rapidly being converted to urban and agricultural uses. We participated in a collaborative field study located in the Amazon region around Manaus, Brazil, in 2014 (Green Ocean Amazon; GoAmazon). This study was designed to comprehensively examine how BVOC emissions (specifically, the most highly emitted non-methane hydrocarbon, isoprene, and lesser studied sesquiterpenes) and their interaction with anthropogenic pollution (i.e., nitrogen oxides, sulfur dioxide, and black carbon) alter the atmosphere’s oxidative capacity, influence secondary aerosol formation, atmospheric composition and, ultimately, affect the earth’s radiation balance and climate. We provide the first hourly, in-situ measurement of 30 sesquiterpenes and 4 diterpenes, roughly estimating that sesquiterpene oxidation contributes to 10-14% of ozone reactive loss by terpenes and at least 0.4–5% (median 1 %) of total submicron OA mass. However, this is likely a low-end estimate, as evidence for additional unaccounted sesquiterpenes and their oxidation products clearly exists. We also provide new perspectives on sulfate, NO x , and particle acidity influencing isoprene-derived SOA, comparing the central Amazon environment with Southeastern U.S.A. summer, representing clean to polluted conditions, respectively. We find that summed concentrations of isoprene-derived SOA tracers correlated with particulate sulfate spanning three orders of magnitude, suggesting that 1 μg m -3 reduction in sulfate corresponds with at least ~0.5 μg m -3 reduction in isoprene-derived SOA. We also find that SOA mass derived from isoprene oxidation in the presence of NO x is primarily comprised of aerosol sulfate bound with isoprene oxidation products (i.e. organosulfates), ~97% in the Amazon and ~55% in the Southeastern U.S. We infer under natural conditions in high isoprene emission regions, preindustrial aerosol sulfate was almost exclusively isoprene-derived organosulfates, which are traditionally thought as representative of anthropogenic influence. We further report the first field observations showing that particle acidity impacts the distribution of isoprene oxidation tracers in the gas and particle phases, providing physicochemical insight into isoprene SOA formation chemistry. Coupled with other co-located measurements by the DOE Atmospheric Radiation Measurement (ARM) team and collaborating PIs at our measurement site (called T3), on the G1 aircraft, and at additional field sites (T0, T1, T2) this data set has been used to understand emission, oxidation, and particle formation pathways at the molecular level, to elucidate how these pathways change when influenced by anthropogenic sources, and to evaluate their importance for the atmospheric budget of aerosols and the earth’s radiation balance on regional scales. Recommendations: Further constraint of the role of sesquiterpenes on ozone (O 3 ) reactivity and SOA formation is limited by the availability of authentic standards and synthesized compounds of sesquiterpenes and their oxidation products. Future research efforts should focus on making such standards available via custom synthesis to allow for accurate quantification and focused oxidation experiments that will fully elucidate the chemistry of these compounds in the atmosphere. Further, reductions in aerosol sulfate (via SO 2 emissions control) continues to be one of the most effective methods to reduce SOA formation from isoprene, but the concerted role of ammonia (NH 3 ) gas emissions from (agricultural) industry and other sources requires more investigation to better understand the role of aerosol acidity in SOA formation and potential controls. As GoAmazon particles can be more acidic compared to areas with greater anthropogenic NH 3 emissions, this promotes relatively greater organosulfate (OS) formation from isoprene even in the presence of NO x . Because OS and inorganic sulfate differ in water uptake properties, this implies preindustrial aerosol sulfate (albeit less abundant) may have been less reflective than current earth system models assume. Further research should investigate the radiative impacts of organic vs inorganic sulfate in aerosols to improve model representation. Finally, future work (currently underway) should include constraint of the contributions of monoterpene (C 10 H 16 ) BVOCs and biomass burning VOCs as precursors to SOA formation in the region as well as their impacts on radiative forcing in the climate system.

54 ENVIRONMENTAL SCIENCES↗

Computer viruses

The worm, Trojan horse, bacterium, and virus are destructive programs that attack information stored in a computer's memory. Virus programs, which propagate by incorporating copies of themselves into other programs, are a growing menace in the late-1980s world of unprotected, networked workstations and personal computers. Limited immunity is offered by memory protection hardware, digitally authenticated object programs,and antibody programs that kill specific viruses. Additional immunity can be gained from the practice of digital hygiene, primarily the refusal to use software from untrusted sources. Full immunity requires attention in a social dimension, the accountability of programmers.

Denning, Peter J.↗

Simple, Secure, Internet Delivery of MOOSE-based Applications

Application packaging and distribution are the final steps for delivering software to end-users; both are frequently neglected when creating scientific software. Commercial businesses rely on electronic distribution systems that have rendered disk drives obsolete. Still, national laboratories continue to rely heavily on removable media to distribute and limit access to controlled applications. With increasing concerns of unauthorized copying of sensitive applications, a modern distribution system that utilizes cryptographically secure communication and authentication protocols has been developed. This new distribution system will secure the chain of custody for nuclear software while simultaneously simplifying access to these tools. This report summarizes four primary advancements made toward the secure distribution of Nuclear Energy Advanced Modeling and Simulation (NEAMS)-developed, Multiphysics Object Oriented Simulation Environment (MOOSE)-based applications: application installation, package distribution, automated package building, and distribution of documentation. NEAMS is currently developing more than ten separate applications based on the open-source MOOSE Framework. Distribution of these applications has primarily been accomplished by distributing source code, with end-users compiling the applications themselves. This work created a mechanism where MOOSE applications can be installed in a similar way to any other software. This allows both administrators and end-users simplified access to runnable executables. With this new installation capability, it was then possible to rethink distribution. A new, secure capability for delivering MOOSE-based applications over the internet has been created. This system requires unique cryptographic tokens for authentication, greatly securing the custody chain for software. Once granted access, installation of any NEAMS code can be accomplished with these terminal commands: "conda install ncrc" "ncrc install ncrc-bison." After these two commands (and authenticating) the BISON application will be securely down- loaded from Idaho National Laboratory (INL)’s servers, installed, and ready to use. To enable this new distribution capability to be successful, the open-source Continuous Integration, Verification, Enhancement, and Testing (CIVET) Continuous Integration (CI) capability was augmented to add Continuous Delivery (CD). CD enables the automated building and packaging of MOOSE-based applications as they are modified by development teams, ensuring that our customers can obtain up-to-date versions of the software at any time. The need for instruction on how to use these applications was addressed through modifications to the MOOSE documentation system. The MooseDocs capability, which enables robust documentation of MOOSE-based applications, has been extended to allow both for the installation of documentation and the packaging of documentation with installed applications. Together, these enhancements form the core of a new, secure distribution mechanism for nuclear simulation tools. In concert with the Nuclear Computational Resource Center (NCRC), NEAMS- developed applications will now be straightforward to obtain securely.

97 MATHEMATICS AND COMPUTING↗

ModuleOT

ModuleOT is an open hardware security platform which provides all features necessary for securing remote energy resources. The platform consists of a physical bump in-the wire device which runs a custom-built application built with Go and Python and leverages AES-NI Instruction set available on modern hardware for cryptographic acceleration. By combining these features, ModuleOT acts as an all-in-one low-cost solution to enable cryptographically secured communications to any critical remote servers or devices. Because the software application has been built using Golang, this source can be easily compiled for different hardware platforms. The module is designed to provide the following core features: (1) encrypted communications across an untrusted network, (2) certificate-based authentication with secure storage, (3) hardware cryptographic acceleration, (4) IP-based whitelisting, (5) local firewall management, and (6) legacy (RS485) device support.

Hasandka, Adarsh↗

Information Power Grid: Distributed High-Performance Computing and Large-Scale Data Management for Science and Engineering

We use the term "Grid" to refer to distributed, high performance computing and data handling infrastructure that incorporates geographically and organizationally dispersed, heterogeneous resources that are persistent and supported. This infrastructure includes: (1) Tools for constructing collaborative, application oriented Problem Solving Environments / Frameworks (the primary user interfaces for Grids); (2) Programming environments, tools, and services providing various approaches for building applications that use aggregated computing and storage resources, and federated data sources; (3) Comprehensive and consistent set of location independent tools and services for accessing and managing dynamic collections of widely distributed resources: heterogeneous computing systems, storage systems, real-time data sources and instruments, human collaborators, and communications systems; (4) Operational infrastructure including management tools for distributed systems and distributed resources, user services, accounting and auditing, strong and location independent user authentication and authorization, and overall system security services The vision for NASA's Information Power Grid - a computing and data Grid - is that it will provide significant new capabilities to scientists and engineers by facilitating routine construction of information based problem solving environments / frameworks. Such Grids will knit together widely distributed computing, data, instrument, and human resources into just-in-time systems that can address complex and large-scale computing and data analysis problems. Examples of these problems include: (1) Coupled, multidisciplinary simulations too large for single systems (e.g., multi-component NPSS turbomachine simulation); (2) Use of widely distributed, federated data archives (e.g., simultaneous access to metrological, topological, aircraft performance, and flight path scheduling databases supporting a National Air Space Simulation systems}; (3) Coupling large-scale computing and data systems to scientific and engineering instruments (e.g., realtime interaction with experiments through real-time data analysis and interpretation presented to the experimentalist in ways that allow direct interaction with the experiment (instead of just with instrument control); (5) Highly interactive, augmented reality and virtual reality remote collaborations (e.g., Ames / Boeing Remote Help Desk providing field maintenance use of coupled video and NDI to a remote, on-line airframe structures expert who uses this data to index into detailed design databases, and returns 3D internal aircraft geometry to the field); (5) Single computational problems too large for any single system (e.g. the rotocraft reference calculation). Grids also have the potential to provide pools of resources that could be called on in extraordinary / rapid response situations (such as disaster response) because they can provide common interfaces and access mechanisms, standardized management, and uniform user authentication and authorization, for large collections of distributed resources (whether or not they normally function in concert). IPG development and deployment is addressing requirements obtained by analyzing a number of different application areas, in particular from the NASA Aero-Space Technology Enterprise. This analysis has focussed primarily on two types of users: the scientist / design engineer whose primary interest is problem solving (e.g. determining wing aerodynamic characteristics in many different operating environments), and whose primary interface to IPG will be through various sorts of problem solving frameworks. The second type of user is the tool designer: the computational scientists who convert physics and mathematics into code that can simulate the physical world. These are the two primary users of IPG, and they have rather different requirements. The results of the analysis of the needs of these two types of users provides a broad set of requirements that gives rise to a general set of required capabilities. The IPG project is intended to address all of these requirements. In some cases the required computing technology exists, and in some cases it must be researched and developed. The project is using available technology to provide a prototype set of capabilities in a persistent distributed computing testbed. Beyond this, there are required capabilities that are not immediately available, and whose development spans the range from near-term engineering development (one to two years) to much longer term R&D (three to six years). Additional information is contained in the original.

Johnston, William E.↗

Access Control of Web- and Java-Based Applications

Cybersecurity has become a great concern as threats of service interruption, unauthorized access, stealing and altering of information, and spreading of viruses have become more prevalent and serious. Application layer access control of applications is a critical component in the overall security solution that also includes encryption, firewalls, virtual private networks, antivirus, and intrusion detection. An access control solution, based on an open-source access manager augmented with custom software components, was developed to provide protection to both Web-based and Javabased client and server applications. The DISA Security Service (DISA-SS) provides common access control capabilities for AMMOS software applications through a set of application programming interfaces (APIs) and network- accessible security services for authentication, single sign-on, authorization checking, and authorization policy management. The OpenAM access management technology designed for Web applications can be extended to meet the needs of Java thick clients and stand alone servers that are commonly used in the JPL AMMOS environment. The DISA-SS reusable components have greatly reduced the effort for each AMMOS subsystem to develop its own access control strategy. The novelty of this work is that it leverages an open-source access management product that was designed for Webbased applications to provide access control for Java thick clients and Java standalone servers. Thick clients and standalone servers are still commonly used in businesses and government, especially for applications that require rich graphical user interfaces and high-performance visualization that cannot be met by thin clients running on Web browsers

Tso, Kam S.↗

Photosynthesis-dependent Isoprene Emission from Leaf to Planet in a Global Carbon-chemistry-climate Model

We describe the implementation of a biochemical model of isoprene emission that depends on the electron requirement for isoprene synthesis into the FarquharBallBerry leaf model of photosynthesis and stomatal conductance that is embedded within a global chemistry-climate simulation framework. The isoprene production is calculated as a function of electron transport-limited photosynthesis, intercellular and atmospheric carbon dioxide concentration, and canopy temperature. The vegetation biophysics module computes the photosynthetic uptake of carbon dioxide coupled with the transpiration of water vapor and the isoprene emission rate at the 30 min physical integration time step of the global chemistry-climate model. In the model, the rate of carbon assimilation provides the dominant control on isoprene emission variability over canopy temperature. A control simulation representative of the present-day climatic state that uses 8 plant functional types (PFTs), prescribed phenology and generic PFT-specific isoprene emission potentials (fraction of electrons available for isoprene synthesis) reproduces 50 of the variability across different ecosystems and seasons in a global database of 28 measured campaign-average fluxes. Compared to time-varying isoprene flux measurements at 9 select sites, the model authentically captures the observed variability in the 30 min average diurnal cycle (R2 6496) and simulates the flux magnitude to within a factor of 2. The control run yields a global isoprene source strength of 451 TgC yr1 that increases by 30 in the artificial absence of plant water stress and by 55 for potential natural vegetation.

photosynthesis↗