Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Secure by Design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Spacecraft Data and Relay Management using Delay Tolerant Networking

NASA's demonstration of the successful transmission of relay data through the orbiting Mars Odyssey, Mars Global Surveyor, and Mars Express by the Mars Exploration Rovers has shown not only the benefit of using a relay satellite for multiple landed assets in a deep space environment but also the benefit of international standards for such architecture. As NASA begins the quest defined in the Vision for Exploration with robotic and manned missions to the Moon, continues its study of Mars, and is joined in these endeavors by countries world-wide, landed assets transmitting data through relay satellites will be crucial for completing mission objectives. However, this method of delivery of data will result in increased complexity in routing and prioritization of data transmission as the number of missions increases. Also, there is currently no standard method among organizations conducting such missions to return these data sets to Earth given a complex environment. One possibility for establishing such a standard is for mission designers to deploy protocols which fall under the umbrella of Delay Tolerant Networking (DTN). These developing standards include the Bundle Protocol (BP) which provides a standard, secure, store and forward mechanism designed for high latency and asymmetric communication links and the Licklider Transmission Protocol (LTP) which is used to provide a reliable deep space link transmission service.

network congestion control algorithm↗

Spacecraft data and relay management using delay tolerant networking

NASA’s demonstration of the successful transmission of relay data through the orbiting Mars Odyssey, Mars Global Surveyor, and Mars Express by the Mars Exploration Rovers has shown not only the benefit of using a relay satellite for multiple landed assets in a deep space environment but also the benefit of international standards for such an architecture. As NASA begins the quest defined in the Vision for Exploration with robotic and manned missions to the Moon, continues its study of Mars, and is joined in these endeavors by countries world-wide, landed assets transmitting data through relay satellites will be crucial for completing mission objectives. However, this method of data delivery will result in increased complexity in routing and prioritization of data transmission as the number of missions increases. Also, there is currently no standard method among organizations conducting such missions to return these data sets to Earth given a complex environment. One possibility for establishing such a standard is for mission designers to deploy protocols which fall under the umbrella of Delay Tolerant Networking (DTN). These developing standards include the Bundle Protocol (BP) which provides a standard, secure, store and forward mechanism designed for high latency and asymmetric communication links and the Licklider Transmission Protocol (LTP) which is used to provide a reliable deep space link transmission service.

Torgerson, J. Leigh↗

Derived virtual devices: a secure distributed file system mechanism

This paper presents the design of derived virtual devices (DVDs). DVDs are the mechanism used by the Netstation Project to provide secure shared access to network-attached peripherals distributed in an untrusted network environment. DVDs improve Input/Output efficiency by allowing user processes to perform I/O operations directly from devices without intermediate transfer through the controlling operating system kernel. The security enforced at the device through the DVD mechanism includes resource boundary checking, user authentication, and restricted operations, e.g., read-only access. To illustrate the application of DVDs, we present the interactions between a network-attached disk and a file system designed to exploit the DVD abstraction. We further discuss third-party transfer as a mechanism intended to provide for efficient data transfer in a typical NAP environment. We show how DVDs facilitate third-party transfer, and provide the security required in a more open network environment.

VanMeter, Rodney↗

Custom Turnkey Time and Frequency Systems: A structured, expandable approach

Radiocode Clocks Ltd. have developed a Turnkey Time and Frequency Generation and Distribution, System strategy based upon a bus of three, 'core' signals from which any Time code, Pulse rate or Frequency can be produced. The heart of the system is a ruggedized 19 inch, 3U Single Eurocard chassis constructed from machined 10mm aluminum alloy plate and designed to meet stringent Military, Security and Telecommunications specifications. The chassis is fitted with an advanced multilayer backplane with separate ground planes for analog and digital signals ensuring no degradation of low noise frequency references in the proximity of high speed digital pulse transmissions. The system has been designed to be used in three possible configurations: 1) As a stand alone generation and distribution instrument; 2) As a primary distribution unit in a turnkey Time and Frequency system; and 3) As a secondary distribution unit at a remote location from the Turnkey Time and Frequency System providing regeneration of core signals and correction for transmission delays. When configured as a secondary distribution unit the system will continue to provide usable outputs when one, two or even all three of the 'core' signals are lost. The instrument's placement within a system as a possible single point of system failure has required the development of very high reliability translator, synthesizer, phase locked loop and distribution modules together with a comprehensive alarm and monitoring strategy.

Wright, David F.↗

NASA Technology Utilization House technical support package Summary of results and house description

The Technology Utilization House (Tech House) was designed and constructed to demonstrate to the building industry and the public the benefits of aerospace technology and other new technology that are presently available or will be in very near future. Use of solar energy, conservation of energy and of water, safety, and security were incorporated in the design of the house. The terms to be incorporated into the house and to assist in the design of the house were evaluated. An architectural engineering team was employed to investigate energy conservation ideas, determine cost effectiveness of new materials and systems, and prepare specifications and drawings for the house. The Tech House was constructed during the spring of 1976. All the systems were monitored to insure proper operation, and data were collected during a one year occupancy. Results obtained during the family live-in period, comments on the acceptance of the various energy-saving systems by the family, and suggestions for improvement of the systems are presented.

Source record↗

Secure Container For Discarded Hypodermic Needles

Container designed for safe retention of discarded blood-collecting hypodermic needles and similar sharp objects used in life-science experiments aboard spacecraft. Needles inserted through self-closing lid and retained magnetically. They are inserted, sharp end first, through spring-loaded flap. Long needles and needles on syringes cannot turn around in container. Can be emptied, cleaned, and reused. Used on Earth to provide unusually secure containment of sharp objects.

Lee, Angelene M.↗

Secure Networks for First Responders and Special Forces

When NASA needed help better securing its communications with orbiting satellites, the Agency called on Western DataCom Co., Inc., to help develop a prototype Internet Protocol (IP) router. Westlake, Ohio-based Western DataCom designs, develops, and manufactures hardware that secures voice, video, and data transmissions over any IP-based network. The technology that it jointly developed with NASA is now serving as a communications solution in military and first-response situations.

Source record↗

Land remote sensing commercialization: A status report

The current offer by the United States Department of Commerce to transfer the U.S. land remote sensing program to the private sector is described. A Request for Proposals (RFP) was issued, soliciting offers from U.S. firms to provide a commercial land remote sensing satellite system. Proposals must address a complete system including satellite, communications, and ground data processing systems. Offerors are encouraged to propose to take over the Government LANDSAT system which consists of LANDSAT 4 and LANDSAT D'. Also required in proposals are the market development procedures and plans to ensure that commercialization is feasible and the business will become self-supporting at the earliest possible time. As a matter of Federal Policy, the solicitation is designed to protect both national security and foreign policy considerations. In keeping with these concerns, an offeror must be a U.S. Firm. Requirements for data quality, quantity, distribution and delivery are met by current operational procedures. It is the Government's desire that the Offeror be prepared to develop and operate follow-on systems without Government subsidies. However, to facilitate rapid commercialization, an offeror may elect to include in his proposal mechanisms for short term government financial assistance.

Bishop, W. P.↗

Secure Remote Access Issues in a Control Center Environment

The ISS finally reached an operational state and exists for local and remote users. Onboard payload systems are managed by the Huntsville Operations Support Center (HOSC). Users access HOSC systems by internet protocols in support of daily operations, preflight simulation, and test. In support of this diverse user community, a modem security architecture has been implemented. The architecture has evolved over time from an isolated but open system to a system which supports local and remote access to the ISS over broad geographic regions. This has been accomplished through the use of an evolved security strategy, PKI, and custom design. Through this paper, descriptions of the migration process and the lessons learned are presented. This will include product decision criteria, rationale, and the use of commodity products in the end architecture. This paper will also stress the need for interoperability of various products and the effects of seemingly insignificant details.

Pitts, Lee↗

Reconfigurable Hardware Adapts to Changing Mission Demands

A new class of computing architectures and processing systems, which use reconfigurable hardware, is creating a revolutionary approach to implementing future spacecraft systems. With the increasing complexity of electronic components, engineers must design next-generation spacecraft systems with new technologies in both hardware and software. Derivation Systems, Inc., of Carlsbad, California, has been working through NASA s Small Business Innovation Research (SBIR) program to develop key technologies in reconfigurable computing and Intellectual Property (IP) soft cores. Founded in 1993, Derivation Systems has received several SBIR contracts from NASA s Langley Research Center and the U.S. Department of Defense Air Force Research Laboratories in support of its mission to develop hardware and software for high-assurance systems. Through these contracts, Derivation Systems began developing leading-edge technology in formal verification, embedded Java, and reconfigurable computing for its PF3100, Derivational Reasoning System (DRS ), FormalCORE IP, FormalCORE PCI/32, FormalCORE DES, and LavaCORE Configurable Java Processor, which are designed for greater flexibility and security on all space missions.

Source record↗

Secure Payload Access to the International Space Station

The ISS finally reached an operational state and exists for local and remote users. Onboard payload systems are managed by the Huntsville Operations Support Center (HOSC). Users access HOSC systems by internet protocols in support of daily operations, preflight simulation, and test. In support of this diverse user community, a modem security architecture has been implemented. The architecture has evolved over time from an isolated but open system to a system which supports local and remote access to the ISS over broad geographic regions. This has been accomplished through the use of an evolved security strategy, PKI, and custom design. Through this paper, descriptions of the migration process and the lessons learned are presented. This will include product decision criteria, rationale, and the use of commodity products in the end architecture. This paper will also stress the need for interoperability of various products and the effects of seemingly insignificant details.

Pitts, R. Lee↗

Experimental study of flow past turbine blades

The requirements on gas turbines for aircraft power units, namely, adequate efficiency, operation at high gas temperatures, low weight, and small dimensions, must be taken into consideration during the design of the blading. To secure good efficiency, it is necessary that the gas flow past the blades as smoothly as possible without separation. This is relatively easily obtainable in the accelerated flow of turbine blading, if the blade spacing is chosen small enough. A small blade spacing, however, is detrimental to the other requirements outlined above. Operation at high gas temperatures usually calls for blade cooling. This cooling is associated with a power input that lowers the turbine efficiency. Since the amount of heat that must be carried off for coding a blade can be influenced rather little, the gross power input for a turbine stage can be reduced by keeping the number of blades to a minimum, that is, with blades of high spacing ratio. But here also a limit is imposed, the exceeding of which is followed by separation of flow. Hence the requirement of finding blade forms on which the flow separates at rather high spacing ratios .

Eckert, E.↗

Air Traffic Management Blockchain Infrastructure for Security, Authentication, and Privacy

Current radar-based air traffic service providers may preserve privacy for military and corporate operations by procedurally preventing public release of selected flight plans, position, and state data. The FAA mandate for national adoption of Automatic Dependent Surveillance Broadcast (ADS-B) in 2020 does not include provisions for maintaining these same aircraft-privacy options, nor does it address the potential for spoofing, denial of service, and other well-documented risk factors. This paper presents an engineering prototype that embodies a design and method that may be applied to mitigate these ADS-B security issues. The design innovation is the use of an open source permissioned blockchain framework to enable aircraft privacy and anonymity while providing a secure and efficient method for communication with Air Traffic Services, Operations Support, or other authorized entities. This framework features certificate authority, smart contract support, and higher-bandwidth communication channels for private information that may be used for secure communication between any specific aircraft and any particular authorized member, sharing data in accordance with the terms specified in the form of smart contracts. The prototype demonstrates how this method can be economically and rapidly deployed in a scalable modular environment.

air traffic privacy & authentication↗

Air Traffic Management Blockchain Infrastructure for Security, Authentication, and Privacy

Current radar-based air traffic service providers may preserve privacy for military and corporate operations by procedurally preventing public release of selected flight plans, position, and state data. The FAA mandate for national adoption of Automatic Dependent Surveillance Broadcast (ADS-B) in 2020 does not include provisions for maintaining these same aircraft-privacy options, nor does it address the potential for spoofing, denial of service, and other well-documented risk factors. This paper presents an engineering prototype that embodies a design and method that may be applied to mitigate these ADS-B security issues. The design innovation is the use of an open source permissioned blockchain framework to enable aircraft privacy and anonymity while providing a secure and efficient method for communication with Air Traffic Services, Operations Support, or other authorized entities. This framework features certificate authority, smart contract support, and higher-bandwidth communication channels for private information that may be used for secure communication between any specific aircraft and any particular authorized member, sharing data in accordance with the terms specified in the form of smart contracts. The prototype demonstrates how this method can be economically and rapidly deployed in a scalable modular environment.

ADS-B cybersecurity↗

The Spaceport Command and Control System Security Assessor Project

This Summer, I worked as a National Aeronautics and Space Administration (NASA) Internships and Fellowships (NIF) intern under my mentor, Jill Giles within the Software Engineering Branch. Within this project, I worked alongside the Cyber Security branch to identify a list of Commercial Off the Shelf (COTS) software to analyze, research, and gain insight about potential vulnerabilities within the software that could become a threat of attack. After identifying the list of COTS software, my team and I used Microsoft Excel to create a worksheet to easily organize and design a questionnaire about the software. Security reports weregiven to us to identify the software used on the machines in the firing rooms. With these reports, we created a script that would populate the database with the software information to identify potential security weaknesses of COTS software.The goal of the project was to produce a final report, summarizing the most vulnerable launch control system servers and configurations and document vulnerabilities, residual risk, likelihood, and consequence. This project is important for the Cyber Security and Information Technology branches because it will identify security weaknesses and help to mitigate risk. From the Spaceport Command and Control System Security Assessor Project, I learned how to properly identify weaknesses and vulnerabilities within software and how to mitigate the risks within the software. This project also taught me how to create databases using scripts and input files.

Destani Satora Van Arsdalen↗

D3: A Collaborative Infrastructure for Aerospace Design

DARWIN is a NASA developed, Internet-based system for enabling aerospace researchers to securely and remotely access and collaborate on the analysis of aerospace vehicle design data, primarily the results of wind-tunnel testing and numeric (e.g., computational fluid dynamics) model executions. DARWIN captures, stores and indexes data, manages derived knowledge (such as visualizations across multiple data sets) and provides an environment for designers to collaborate in the analysis of the results of testing. DARWIN is an interesting application because it supports high volumes of data, integrates multiple modalities of data display (e.g. images and data visualizations), and provides non-trivial access control mechanisms. DARWIN enables collaboration by allowing not only sharing visualizations of data, but also commentary about and view of data.

Walton, Joan↗

Design of infrared astronomical satellite /IRAS/ primary mirror mounts

The design of an operational mount to rigidly secure the primary mirror to its baseplate without the introduction of figure error always proves to be a major task on diffraction limited optical systems. A summary of the design of the Infrared Astronomical Satellite (IRAS) primary mirror mount is given. The mirror was designed to be alligned and tested at room temperature and operated in a zero 'g' field at temperatures of 2K. To minimize overstressing, a stiffness requirement of greater than 150 Hz was required for cold launch and room temperature vibration acceptance testing. Additional isolation was required to minimize strains, introduced via the mounting base, due to thermal and mechanical distortions.

Schreibman, M.↗

OSIRIS-REx Touch-And-Go (TAG) Mission Design and Analysis

The Origins Spectral Interpretation Resource Identification Security Regolith Explorer (OSIRIS-REx) mission is a NASA New Frontiers mission launching in 2016 to rendezvous with the near-Earth asteroid (101955) 1999 RQ36 in late 2018. After several months in formation with and orbit about the asteroid, OSIRIS-REx will fly a Touch-And-Go (TAG) trajectory to the asteroid s surface to obtain a regolith sample. This paper describes the mission design of the TAG sequence and the propulsive maneuvers required to achieve the trajectory. This paper also shows preliminary results of orbit covariance analysis and Monte-Carlo analysis that demonstrate the ability to arrive at a targeted location on the surface of RQ36 within a 25 meter radius with 98.3% confidence.

Berry, Kevin↗