Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “source authentication”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Fermilab s Transition to Token Authentication

Fermilab is the first High Energy Physics institution to transition from X.509 user certificates to authentication tokens in production systems. All of the experiments that Fermilab hosts are now using JSON Web Token (JWT) access tokens in their grid jobs. Many software components have been either updated or created for this transition, and most of the software is available to others as open source. The tokens are defined using the WLCG Common JWT Profile. Token attributes for all the tokens are stored in the Fermilab FERRY system which generates the configuration for the CILogon token issuer. High security-value refresh tokens are stored in Hashicorp Vault configured by htvault-config, and JWT access tokens are requested by the htgettoken client through its integration with HTCondor. The Fermilab job submission system jobsub was redesigned to be a lightweight wrapper around HTCondor. For automated job submissions a managed tokens service was created to reduce duplication of effort and knowledge of how to securely keep tokens active. The existing Fermilab file transfer tool ifdh was updated to work seamlessly with tokens, as well as the Fermilab POMS (Production Operations Management System) which is used to manage automatic job submission and the RCDS (Rapid Code Distribution System) which is used to distribute analysis code via the CernVM FileSystem. The dCache storage system was reconfigured to accept tokens for authentication in place of X.509 proxy certificates. As some services and sites have not yet implemented token support, proxy certificates are still sent with jobs for backwards compatibility but some experiments are beginning to transition to stop using them. There have been some glitches and learning curve issues but in general the system has been performing well and is being improved as operational problems are addressed.

Dykstra, David↗

Fermilab's Transition to Token Authentication

Fermilab is the first High Energy Physics institution to transition from X.509 user certificates to authentication tokens in production systems. All the experiments that Fermilab hosts are now using JSON Web Token (JWT) access tokens in their grid jobs. Many software components have been either updated or created for this transition, and most of the software is available to others as open source. The tokens are defined using the WLCG Common JWT Profile. Token attributes for all the tokens are stored in the Fermilab FERRY system which generates the configuration for the CILogon token issuer. High security-value refresh tokens are stored in Hashicorp Vault configured by htvault-config, and JWT access tokens are requested by the htgettoken client through its integration with HTCondor. The Fermilab job submission system jobsub was redesigned to be a lightweight wrapper around HTCondor. The grid workload management system GlideinWMS which is also based on HTCondor was updated to use tokens for pilot job submission. For automated job submissions a managed tokens service was created to reduce duplication of effort and knowledge of how to securely keep tokens active. The existing Fermilab file transfer tool ifdh was updated to work seamlessly with tokens, as well as the Fermilab POMS (Production Operations Management System) which is used to manage automatic job submission and the RCDS (Rapid Code Distribution System) which is used to distribute analysis code via the CernVM FileSystem. The dCache storage system was reconfigured to accept tokens for authentication in place of X.509 proxy certificates. As some services and sites have not yet implemented token support, proxy certificates are still sent with jobs for backwards compatibility, but some experiments are beginning to transition to stop using them.

Dykstra, Dave [Fermilab] (ORCID:0000000326539015)↗

Verifying Cyber Implementation Best Practices With Malcolm

Network traffic analysis can reveal a lot about what's right or wrong with a network's cybersecurity footing. Using Malcolm, a powerful open-source network traffic analysis tool suite for network security monitoring, cyber analysts and asset owners can validate cybersecurity best practices and uncover red flags in network configuration, including: proper network segmentation east-west (cross-segment) and north-south traffic unsecure or outdated network protocols authentication using clear text credentials rogue devices and services unexpected protocols (e.g., IPv6, DNS, DHCP, update checks, etc.) suspicious file transfers

99 GENERAL AND MISCELLANEOUS↗

Access Control of Web and Java Based Applications

Cyber security has gained national and international attention as a result of near continuous headlines from financial institutions, retail stores, government offices and universities reporting compromised systems and stolen data. Concerns continue to rise as threats of service interruption, and spreading of viruses become ever more prevalent and serious. Controlling access to application layer resources is a critical component in a layered security solution that includes encryption, firewalls, virtual private networks, antivirus, and intrusion detection. In this paper we discuss the development of an application-level access control solution, based on an open-source access manager augmented with custom software components, to provide protection to both Web-based and Java-based client and server applications.

cybersecurity↗

A Prototype Software to Demonstrate a Data Catalog for Hanford Environmental Datasets

Ensuring that data on long-term environmental remediation at the Hanford Site is high-quality, traceable, and easily accessible is an ongoing challenge, complicated by decades of data collection, multiple contractors maintaining data sources, and the wide range of data types. A centralized data catalog, known as the Hanford Environmental Information and Data Index (HEIDI), has been under development as part of the Hanford Environmental Data Management (HEDM) program to address these challenges. HEIDI fulfills a critical need to bring together a wide range of data types and sizes from multiple authoritative data sources, while documenting the data pedigree and quality information (i.e., traceable to the data source/originator). This document describes additional development and maturation of the HEIDI prototype. Key accomplishments included deploying the catalog software, Esri Geoportal Server, on a server accessible to Hanford Local Area Network users, conducting cybersecurity evaluations, investigating integrated authentication solutions, and conducting functional testing of the catalog prototype. The server-based deployment enabled targeted feedback, leading to enhancements including improved accessibility features and an expanded metadata schema. Specifications for the server-based deployment of the prototype catalog and the HEIDI metadata schema are provided in this document to support subsequent HEIDI deployment by the U.S. Department of Energy Richland Operations Office.

54 ENVIRONMENTAL SCIENCES↗

Open Source Service Agent (OSSA) in the intelligence community's Open Source Architecture

The Community Open Source Program Office (COSPO) has developed an architecture for the intelligence community's new Open Source Information System (OSIS). The architecture is a multi-phased program featuring connectivity, interoperability, and functionality. OSIS is based on a distributed architecture concept. The system is designed to function as a virtual entity. OSIS will be a restricted (non-public), user configured network employing Internet communications. Privacy and authentication will be provided through firewall protection. Connection to OSIS can be made through any server on the Internet or through dial-up modems provided the appropriate firewall authentication system is installed on the client.

Fiene, Bruce F.↗

Air Traffic Management Blockchain Infrastructure for Security, Authentication, and Privacy

Current radar-based air traffic service providers may preserve privacy for military and corporate operations by procedurally preventing public release of selected flight plans, position, and state data. The FAA mandate for national adoption of Automatic Dependent Surveillance Broadcast (ADS-B) in 2020 does not include provisions for maintaining these same aircraft-privacy options, nor does it address the potential for spoofing, denial of service, and other well-documented risk factors. This paper presents an engineering prototype that embodies a design and method that may be applied to mitigate these ADS-B security issues. The design innovation is the use of an open source permissioned blockchain framework to enable aircraft privacy and anonymity while providing a secure and efficient method for communication with Air Traffic Services, Operations Support, or other authorized entities. This framework features certificate authority, smart contract support, and higher-bandwidth communication channels for private information that may be used for secure communication between any specific aircraft and any particular authorized member, sharing data in accordance with the terms specified in the form of smart contracts. The prototype demonstrates how this method can be economically and rapidly deployed in a scalable modular environment.

air traffic privacy & authentication↗

Air Traffic Management Blockchain Infrastructure for Security, Authentication, and Privacy

Current radar-based air traffic service providers may preserve privacy for military and corporate operations by procedurally preventing public release of selected flight plans, position, and state data. The FAA mandate for national adoption of Automatic Dependent Surveillance Broadcast (ADS-B) in 2020 does not include provisions for maintaining these same aircraft-privacy options, nor does it address the potential for spoofing, denial of service, and other well-documented risk factors. This paper presents an engineering prototype that embodies a design and method that may be applied to mitigate these ADS-B security issues. The design innovation is the use of an open source permissioned blockchain framework to enable aircraft privacy and anonymity while providing a secure and efficient method for communication with Air Traffic Services, Operations Support, or other authorized entities. This framework features certificate authority, smart contract support, and higher-bandwidth communication channels for private information that may be used for secure communication between any specific aircraft and any particular authorized member, sharing data in accordance with the terms specified in the form of smart contracts. The prototype demonstrates how this method can be economically and rapidly deployed in a scalable modular environment.

ADS-B cybersecurity↗

A multimodal and integrated approach to interrogate human kidney biopsies with rigor and reproducibility: guidelines from the Kidney Precision Medicine Project

Comprehensive and spatially mapped molecular atlases of organs at a cellular level are a critical resource to gain insights into pathogenic mechanisms and personalized therapies for diseases. The Kidney Precision Medicine Project (KPMP) is an endeavor to generate three-dimensional (3-D) molecular atlases of healthy and diseased kidney biopsies by using multiple state-of-the-art omics and imaging technologies across several institutions. Obtaining rigorous and reproducible results from disparate methods and at different sites to interrogate biomolecules at a single-cell level or in 3-D space is a significant challenge that can be a futile exercise if not well controlled. Here we describe a “follow the tissue” pipeline for generating a reliable and authentic single-cell/region 3-D molecular atlas of human adult kidney. Our approach emphasizes quality assurance, quality control, validation, and harmonization across different omics and imaging technologies from sample procurement, processing, storage, shipping to data generation, analysis, and sharing. We established benchmarks for quality control, rigor, reproducibility, and feasibility across multiple technologies through a pilot experiment using common source tissue that was processed and analyzed at different institutions and different technologies. A peer review system was established to critically review quality control measures and the reproducibility of data generated by each technology before their being approved to interrogate clinical biopsy specimens. The process established economizes the use of valuable biopsy tissue for multiomics and imaging analysis with stringent quality control to ensure rigor and reproducibility of results and serves as a model for precision medicine projects across laboratories, institutions and consortia.

59 BASIC BIOLOGICAL SCIENCES↗

ToF-SIMS evaluation of PEG-related mass peaks and applications in PEG detection in cosmetic products

Polyethylene glycols (PEGs) are used in industrial, medical, health care, and personal care applications. The cycling and disposal of synthetic polymers like PEGs pose significant environmental concerns. Detecting and monitoring PEGs in the real world calls for immediate attention. This study unveils the efficacy of time-of-flight secondary ion mass spectrometry (ToF-SIMS) as a reliable approach for precise analysis and identification of reference PEGs and PEGs used in cosmetic products. By comparing SIMS spectra, we show remarkable sensitivity in pinpointing distinctive ion peaks inherent to various PEG compounds. Moreover, the employment of principal component analysis effectively discriminates compositions among different samples. Notably, the application of SIMS two-dimensional image analysis visually portrays the spatial distribution of various PEGs as reference materials. The same is observed in authentic cosmetic products. The application of ToF-SIMS underscores its potential in distinguishing PEGs within intricate environmental context. ToF-SIMS provides an effective solution to studying emerging environmental challenges, offering straightforward sample preparation and superior detection of synthetic organics in mass spectral analysis. These features show that SIMS can serve as a promising alternative for evaluation and assessment of PEGs in terms of the source, emission, and transport of anthropogenic organics.

36 MATERIALS SCIENCE↗

Risk of Adverse Health and Performance Effects of Celestial Dust Exposure

Crew members can be directly exposed to celestial dust in several ways. After crew members perform extravehicular activities (EVAs), they may introduce into the habitat dust that will have collected on spacesuits and boots. Cleaning of the suits between EVAs and changing of the Environmental Control Life Support System filters are other operations that could result in direct exposure to celestial dusts. In addition, if the spacesuits used in exploration missions abrade the skin, as current EVA suits have, then contact with these wounds would provide a source of exposure. Further, if celestial dusts gain access to a suit's interior, as was the case during the Apollo missions, the dust could serve as an additional source of abrasions or enhance suit-induced injuries. When a crew leaves the surface of a celestial body and returns to microgravity, the dust that is introduced into the return vehicle will "float," thus increasing the opportunity for ocular and respiratory injury. Because the features of the respirable fraction of lunar dusts indicate they could be toxic to humans, NASA conducted several studies utilizing lunar dust simulants and authentic lunar dust to determine the unique properties of lunar dust that affect physiology, assess the dermal and ocular irritancy of the dust, and establish a permissible exposure limit for episodic exposure to airborne lunar dust during missions that would involve no more than 6 months stay on the lunar surface. Studies, with authentic lunar soils from both highland (Apollo 16) and mare (Apollo17) regions demonstrated that the lunar soil is highly abrasive to a high fidelity model of human skin. Studies of lunar dust returned during the Apollo 14 mission from an area of the moon in which the soils were comprised of mineral constituents from both major geological regions (highlands and mares regions) demonstrated only minimal ocular irritancy, and pulmonary toxicity that was less than the highly toxic terrestrial crystalline silica (Permissible Exposure Limit [PEL] 0.05 mg/m3) but more toxic than the nuisance dust titanium dioxide (TiO2 [PEL 5.0 mg/m3]). A PEL for episodic exposure to airborne lunar dust during a six-month stay on the lunar surface was established, in consultation with an independent, extramural panel of expert pulmonary toxicologists, at 0.3 mg/m3. The PEL provided for lunar dust is limited to the conditions and exposure specified therefore additional research remains to be accomplished with lunar dust to further address the issues of activation, address other areas of more unique lunar geology (Glotch et al., 2010; Greenhagen et al., 2010), examine potential toxicological effects of inhaled or ingested dust upon other organ systems, such cardiovascular, nervous systems, and examine effects of acute exposure to massive doses of dust such as may occur during off-nominal situations. Work to support the establishment of PELs for Martian dust and dusts of asteroids remains to be accomplished. The literature that describes health effects of exposure to toxic terrestrial dusts provides substantial basis for concern that prolonged exposure to respirable celestial dust could be detrimental to human health. Celestial bodies where a substantial portion of the dust is in the respirable range or where the dusts have large reactive surface areas or contain transition metals or volatile organics, represent greater risks of adverse effects from exposure to the dust. It is possible that in addition to adverse effects to the respiratory system, inhalation and ingestion of celestial dusts could pose risks to other systems

Scully, Robert R.↗

Module-OT: A Hardware Security Module for Operational Technology

Increased penetration levels of renewable energy and other types of distributed energy resources (DERs) on the modern electric grid-combined with technological advancements for electric system monitoring and control-introduce new cyberattack vectors and increase the cyberattack surface of energy systems. According to the IEEE Std. 1547-2018, DERs must use Modbus, Distributed Network Protocol 3 (DNP3), or Smart Energy Profile 2.0 (SEP2) as their communication protocol. Previous research identified several vulnerabilities and security breaches in each one of these communication protocols; despite this, existing standards for DERs do not recommend cybersecurity measures. In order to reduce vulnerabilities in power distribution systems, this paper presents a novel open-source hardware security module that improves both information and operational security to better protect data and communications on the distribution grid. The security hardware is called “module for operational technology,” or simply Module-OT, and it has been validated and tested in an emulated distribution system application. Module-OT is integrated within a communication system in the transport layer of the Open Systems Interconnection (OSI) model. It improves system security through encryption, authentication, authorization, certificate management, and user access control. The main advancement of Module-OT is the addition of hardware cryptographic acceleration that improves the overall communication performance in terms of end-to-end latency.

70 PLASMA PHYSICS AND FUSION TECHNOLOGY↗

Oak Ridge National Laboratory Technical Input for the Nuclear Regulatory Commission Review of the 2017 Edition of ASME Section III, Division 5, ‘High Temperature Reactors’

To assist the Nuclear Regulatory Commission in its decision making on endorsement of the American Society for Mechanical Engineers Boiler and Pressure Vessel Code Section III, Division 5 (2017 Edition) for development of advanced non-light water reactors, the following Division 5 portions were reviewed: Article HBB-2000 Material; Article HCB-2000 Material; Article HGB-2000 Material; Mandatory Appendix HBB-I-14 Tables and Figures; and, Nonmandatory Appendix HBB-U Guidelines for Restricted Material Specifications to Improve Performance in Certain Service Applications. In addition to the 2017 Edition, the same parts of the 2019 Edition have also been reviewed as indicated in various sections of the report. This review was conducted by a collaboration of national laboratory and private sector participants with significant industrial experience, including some heavy lifting and deep diving from Clarus Consulting, LLC., all intended to achieve an objective, independent, and practical perspective. The report provides recommendations, descriptions of the evaluation methods, and the source references for the data used. To build confidence required for endorsement of the Code, this review was conducted as a verification and validation of the above Code contents. The objective of verification is to ensure that the Code is free of error – direct or implied; contains the information needed for its use, including proper coverage of the Code-specified materials for the intended application, and completeness and adequacy of references to other portions of the Code. The objective of validation is to authenticate that the Code tabulations and graphs represent design inputs consistent with what are determined using rules and methods specified by the Code. The authentication process used data that were assembled and/or generated independent of Code development, while the methods of analysis followed Code-specified methods where appropriate. The designated portions for this review cover the five alloys codified for high temperature reactor applications in Division 5, i.e. 316 SS, 304 SS, 800H, 2¼Cr-1Mo, and 9Cr-1Mo-V, regarding their general requirements, permitted specifications and design stress intensity values for pressure-retaining applications, deterioration in service, fatigue acceptance test, permissible weld materials, tensile and yield strength, expected minimum stress-to-rupture values (including for Alloy 718), weld stress rupture factors, permissible materials for bolting use, and restricted specifications in certain service applications. Additionally, stress intensity values for bolting materials including 316 SS, 304 SS and alloy 718 were reviewed. Analysis and discussion are also provided on contents outside of these designated Code portions where it was deemed relevant and necessary to develop a technically sound understanding of issues relating to the designated portions. Due to unavailability of sufficient test data on welds during the review period, the weld stress rupture factors in Tables HBB-I-10.14A to E, which cover a total of ten tables for the five alloys welded with twenty-eight different weld metals (some with similar properties), have been deferred to a future review effort. The review identified mainly two types of issues. The first type includes instances where the Code is found factually incomplete or incorrect, such as obsolete materials specifications listings, missing tabulation of stresses for bolting. Changes to the Code are recommended in these cases. The second type of issue includes instances where the Code tabulations and graphs are found to be less conservative than the review analysis results. In these cases, recommendations are made for further review and consideration where the difference in conservatism exceeds 10%, which is our threshold for questioning technical adequacy, meriting a risk assessment by the Nuclear Regulatory Commission and/or reactor designers. It is noted that this effort has been executed using all available data and established methods of analysis, including methods and criteria specified and used by the Code. As such, the findings that are presented in quantitative detail, in a format for convenient comparison with the Code, and with identification of where further review is recommended, should provide a sound technical basis for decisions about quantifying the implications of the reduced design margins and technical adequacy/inadequacy to form a basis for conditioning specific Code tabulation values on endorsement. Recommendations for specific changes to the Code, however, entail design conservatism considerations beyond the scope of this review effort, and are not made in this report.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

DeepLynx Ecosystem 2025

Poor data integration and governance continue to plague complex engineering projects, resulting in missed cost, schedule, and performance targets. Departments operate in isolated systems with manual data exchange, creating fragmented information that compounds errors and leads to significant delays and cost overruns. The DeepLynx ecosystem addresses these challenges through an open-source, modular data management platform that transforms fragmented project data into an integrated digital thread. Built on a federated microservice architecture, the ecosystem comprises seven specialized tools centered around DeepLynx Nexus, a unified data catalog with hierarchical organization and graph-based navigation capabilities. The ecosystem includes: DeepLynx Stream for real-time timeseries data ingestion from industrial sources; DeepLynx Ingest for governed data uploads with formal review workflows; DeepLynx Lattice for ontology-based entity and relationship extraction; DeepLynx Run for workflow orchestration and secure AI/ML compute; DeepLynx Visualize for 3D digital twin visualization; and DeepLynx Insight for AI-assisted document analysis with traceable, grounded responses. Deployable in cloud, on-premise, or hybrid environments using containerized Docker applications and Helm charts, the DeepLynx ecosystem provides flexible infrastructure that adapts to organizational requirements. By consolidating project data into a unified data lake with role-based access controls and OAuth2 authentication, DeepLynx enables digital thread and digital twin capabilities that improve decision-making, reduce risk, and support complex engineering workflows throughout the project lifecycle.

42 - ENGINEERING↗

Cyber–Physical System Security of Distribution Systems

The Information and Communications Technology (ICT) for control and monitoring of power systems is a layer on top of the physical power system infrastructure. The cyber system and physical power system components form a tightly coupled Cyber–Physical System (CPS). Sources of vulnerabilities arise from the computing and communication systems of the cyber–power grid. Cyber intrusions targeting the power grid are serious threats to the reliability of electricity supply that is critical to society and the economy. In a typical Information Technology environment, numerous attack scenarios have shown how unauthorized users can access and manipulate protected information from a network domain. The need for cyber security has led to industry standards that power grids must meet to ensure that the monitoring, operation, and control functions are not disrupted by cyber intrusions. Cyber security technologies such as encryption and authentication have been deployed on the CPS. Intrusion or anomaly detection and mitigation tools developed for power grids are emerging. Furthermore, this survey paper provides the basic concepts of cyber vulnerabilities of distribution systems and CPS security. The important ICT subjects for distribution systems covered in this paper include Supervisory Control And Data Acquisition, Distributed Energy Resources, including renewable energy and smart meters.

97 MATHEMATICS AND COMPUTING↗

Quantum Chemistry Calculations for Metabolomics

A primary goal of metabolomics and exposomics studies is to fully characterize the small molecule composition of complex biological and environmental samples. However, despite advances in analytical technologies over the past two decades, the majority of small molecules in complex samples are not readily identifiable due to the immense structural and chemical diversi-ty present within the metabolome and exposome. Current gold-standard identification methods rely on reference libraries built using authentic chemical materials (“standards”), which are not available for most molecules. Computational quantum chemis-try methods, which can be used to calculate chemical properties that are then measured by analytical platforms, offer an alter-native route for building reference libraries, i.e., in silico libraries for “standards-free” identification. In this review, we cover the major roadblocks currently facing metabolomics and discuss applications where quantum chemistry calculations offer a solu-tion. Several successful examples for nuclear magnetic resonance spectroscopy, ion mobility spectrometry, infrared spectros-copy, and mass spectrometry methods are reviewed. Finally, we consider current best practices, sources of error, and provide an outlook for quantum chemistry calculations in metabolomics and exposomics studies. We expect this review will inspire researchers in the field of small molecule identification to accelerate adoption of in silico methods for generation of reference libraries and to add quantum chemistry calculations as another tool at their disposal to characterize complex samples.

Metabolism↗

The MY NASA DATA Project

On the one hand, locating the right dataset, then figuring out how to use it, is a daunting task that is familiar to almost any scientist or graduate student in the fields of Earth system science. On the other hand, the ability to explore authentic Earth system science data, through inquiry-based education, is an important goal in US national education standards. Fortunately, in the digital age, tools are emerging that can make such data exploration commonplace at all educational levels. This paper describes the conception and development of one project that aims to bridge this gap: Mentoring and inquiry using NASA Data on Atmospheric and Earth science for Teachers and Amateurs (MY NASA DATA; mynasadata.larc.nasa.gov). With funding from NASA's Science Mission Directorate, this project was launched in early 2004 with the aim of developing microsets and identifying other enablers for making data accessible. A key feature of the project is a Live Access Server, the first educational implementation of this open source software, developed by NOAA, that makes it possible to explore multiple data formats through a single interface. This powerful tool is made more useful to the primary target audiences (K-12 and amateur scientists) through careful selection of the data offered, user-friendly explanations of the tool itself, and age-appropriate explanations of the parameters. However experience already shows that graduate students and even practicing scientists can also make use of this resource. The website also hosts teacher-contributed lesson plans, and seeks to feature reports of research projects that use the data.

Chambers, Lin H.↗

A Privacy-Preserving Cyber Threat Intelligence Sharing System

Cyber Threat Intelligence (CTI) is a key resource for developing defensive strategies against potential cyber adversaries. Entities typically access CTI through open-source platforms, national agencies, or specialized commercial services. However, the bi-directional exchange of CTI is hindered by organizational trust boundaries, which complicate the sharing processes between entities and CTI providers. Centralized CTI services benefit from receiving suspicious cyber observables such as IP addresses, domain names, and email addresses from various entities. The aggregation allows for the correlation of widespread adversarial activities to enhance the alert and response mechanisms across the network of involved parties. Despite these benefits, openly sharing such observables incurs potential legal, regulatory, and reputational risks for the disclosing entities.This paper introduces a system designed to facilitate the secure exchange of cyber observables across trust boundaries without compromising the anonymity of the sharing entities. Here, we propose an architecture that leverages common web protocols alongside zero-knowledge proofs to authenticate members while maintaining anonymity. Additionally, we outline a privacy model tailored for STIX (Structured Threat Information eXpression) cyber observables to minimize the risk of inadvertently disclosing private information. Through our threat models, we assess the privacy implications of our proposed system and demonstrate its potential to enhance collaborative cyber defense efforts without exposing entities to undue risk.

BBS+ Signatures↗