Engineering PapersSearch

SEARCH · Engineering Papers

Results for “performance based security”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Addressing the Tension Between Strong Perimeter Control an Usability

This paper describes a strong perimeter control system for a general purpose processing system, with the perimeter control system taking significant steps to address usability issues, thus mitigating the tension between strong perimeter protection and usability. A secure front end enforces two-factor authentication for all interactive access to an enclave that contains a large supercomputer and various associated systems, with each requiring their own authentication. Usability is addressed through a design in which the user has to perform two-factor authentication at the secure front end in order to gain access to the enclave, while an agent transparently performs public key authentication as needed to authenticate to specific systems within the enclave. The paper then describes a proxy system that allows users to transfer files into the enclave under script control, when the user is not present to perform two-factor authentication. This uses a pre-authorization approach based on public key technology, which is still strongly tied to both two-factor authentication and strict control over where files can be transferred on the target system. Finally the paper describes an approach to support network applications and systems such as grids or parallel file transfer protocols that require the use of many ports through the perimeter. The paper describes a least privilege approach that dynamically opens ports on a host-specific, if-authorized, as-needed, just-in-time basis.

Hinke, Thomas H.

Control and Non-Payload Communications Generation 1 Prototype Radio Flight Test Report

Unmanned aircraft (UA) represent a new capability that will provide a variety of services in the Government (public) and commercial (civil) aviation sectors. The growth of this potential industry has not yet been realized because of the lack of a common understanding of what is required to safely operate Unmanned Aircraft Systems in the National Airspace System (UAS in the NAS). The desire and ability to fly UA is of increasing urgency. The application of UA to perform national security, defense, scientific, and emergency management are driving the critical need for less restrictive access by UA to the NAS. Existing Federal Aviation Regulations, procedures, and technologies do not allow routine UA access to the NAS. Access to the NAS is hampered by challenges such as the lack of an onboard pilot to see and avoid other aircraft; the ability of a single pilot or operator to control multiple UA; the reliance on command and control (C2) links; the altitudes, speeds, and duration at which the aircraft fly; and the wide variation in UA size and performance. NASA is working with other Government agencies to provide solutions that reduce technical barriers and make access to the NAS routine. This goal will be accomplished through system-level integration of key concepts, technologies, or procedures and through demonstrations of these integrated capabilities in an operationally relevant environment. This project provides an opportunity to transition the acquired empirical data and knowledge to the Federal Aviation Administration and other stakeholders to help them define the requirements for routine UA access to the NAS.Radio communications channels for UA are currently managed through exceptions and use either Department of Defense frequencies for line-of-sight (LOS) and satellite-based communications links, low-power LOS links in amateur bands, or unlicensed Industrial/Scientific/Medical (ISM) frequencies. None of these frequency bands are designated for safety and regularity of flight. Only recently has radiofrequency (RF) spectrum been allocated by the International Telecommunications Union specifically for commercial UA C2, LOS communication (L-Band: 960 to 1164 MHz, and C-Band: 5030 to 5091 MHz). The safe and efficient integration of UA into the NAS requires the use of protected RF spectrum allocations and a new data communications system that is both secure and scalable to accommodate the potential growth of these new aircraft. Data communications for UA-referred to as control and non-payload communications (CNPC)-will be used to exchange information between a UA and a ground station (GS) to ensure safe, reliable, and effective UA flight operation. The focus of this effort is on validating and allocating new RF spectrum and data link communications to enable civil UA integration into the NAS. Through a cost-sharing cooperative agreement with Rockwell Collins, Inc., the NASA Glenn Research Center is exploring and performing the necessary development steps to realize a prototype UA CNPC system. These activities include investigating signal waveforms and access techniques, developing representative CNPC radio hardware, and executing relevant testing and validation activities. There is no intent to manufacture the CNPC end product, rather the goals are to study, demonstrate, and validate a typical CNPC system that will allow safe and efficient communications within the L-Band and C-Band spectrum allocations. The system is addressing initial "seed" requirements from RTCA, Inc., Special Committee 203 (SC-203) and is on a path to Federal Aviation Administration certification. This report provides results from the flight testing campaign of the Rockwell Collins Generation 1 prototype radio, referred hereafter as the "radio." The radio sets operate within the 960- to 977-MHz frequency band with both air and ground radios using identical hardware. Flight tests involved one aircraft and one GS. Results include discussion of aircraft flight paths and associated radio performance.

Shalkhauser, Kurt A.

Relation of Fuel-Air Ratio to Engine Performance

The tests upon which this report is based were made at the Bureau of Standards between October 1919 and May 1923. From these it is concluded that: (1) with gasoline as a fuel, maximum power is obtained with fuel-air mixtures of from 0.07 to 0.08 pound of fuel per pound of air; (2) maximum power is obtained with approximately the same ratio over the range of air pressures and temperatures encountered in flight; (3) nearly minimum specific fuel consumption is secured by decreasing the fuel content of the charge until the power is 95 per cent of its maximum value. Presumably this information is of most direct value to the carburetor engineer. A carburetor should supply the engine with a suitable mixture. This report discusses what mixtures have been found suitable for various engines. It also furnishes the engine designer with a basis for estimating how much greater piston displacement an engine operating with a maximum economy mixture should have than one operating with a maximum power mixture in order for both to be capable of the same power development.

Sparrow, Stanwood W

Secure, Autonomous, Intelligent Controller for Integrating Distributed Emergency Response Satellite Operations

This report describes a Secure, Autonomous, and Intelligent Controller for Integrating Distributed Emergency Response Satellite Operations. It includes a description of current improvements to existing Virtual Mission Operations Center technology being used by US Department of Defense and originally developed under NASA funding. The report also highlights a technology demonstration performed in partnership with the United States Geological Service for Earth Resources Observation and Science using DigitalGlobe(Registered TradeMark) satellites to obtain space-based sensor data.

Ivancic, William D.

Accessing Wind Tunnels From NASA's Information Power Grid

The NASA Ames wind tunnel customers are one of the first users of the Information Power Grid (IPG) storage system at the NASA Advanced Supercomputing Division. We wanted to be able to store their data on the IPG so that it could be accessed remotely in a secure but timely fashion. In addition, incorporation into the IPG allows future use of grid computational resources, e.g., for post-processing of data, or to do side-by-side CFD validation. In this paper, we describe the integration of grid data access mechanisms with the existing DARWIN web-based system that is used to access wind tunnel test data. We also show that the combined system has reasonable performance: wind tunnel data may be retrieved at 50Mbits/s over a 100 base T network connected to the IPG storage server.

Becker, Jeff

Model-Based Fault Tolerant Control

The Model Based Fault Tolerant Control (MBFTC) task was conducted under the NASA Aviation Safety and Security Program. The goal of MBFTC is to develop and demonstrate real-time strategies to diagnose and accommodate anomalous aircraft engine events such as sensor faults, actuator faults, or turbine gas-path component damage that can lead to in-flight shutdowns, aborted take offs, asymmetric thrust/loss of thrust control, or engine surge/stall events. A suite of model-based fault detection algorithms were developed and evaluated. Based on the performance and maturity of the developed algorithms two approaches were selected for further analysis: (i) multiple-hypothesis testing, and (ii) neural networks; both used residuals from an Extended Kalman Filter to detect the occurrence of the selected faults. A simple fusion algorithm was implemented to combine the results from each algorithm to obtain an overall estimate of the identified fault type and magnitude. The identification of the fault type and magnitude enabled the use of an online fault accommodation strategy to correct for the adverse impact of these faults on engine operability thereby enabling continued engine operation in the presence of these faults. The performance of the fault detection and accommodation algorithm was extensively tested in a simulation environment.

Kumar, Aditya

Payload Performance of TDRS KL and Future Services

NASA has accepted two of the 3nd generation Tracking and Data Relay Satellites, TDRS K, L, and M, designed and built by Boeing Defense, Space Security (DSS). TDRS K, L, and M provide S-band Multiple Access (MA) service and S-band, Ku-band and Ka-band Single Access (SA) services to near Earth orbiting satellites. The TDRS KLM satellites offer improved services relative to the 1st generation TDRS spacecraft, such as: an enhanced MA service featuring increased EIRPs and GT; and Ka-band SA capability which provides a 225 and 650 MHz return service (customer-to-TDRS direction) bandwidth and a 50 MHz forward service (TDRS-to-customer direction) bandwidth. MA services are provided through a 15 element forward phased array that forms up to two beams with onboard active beamforming and a 32 element return phased array supported by ground-based beamforming. SA services are provided through two 4.6m tri-band reflector antennas which support program track pointing and autotrack pointing. Prior to NASAs acceptance of the satellites, payload on-orbit testing was performed on each satellite to determine on-orbit compliance with design requirements. Performance parameters evaluated include: EIRP, GT, antenna gain patterns, SA antenna autotrack performance, and radiometric tracking performance. On-orbit antenna calibration and pointing optimization was also performed on the MA and SA antennas including 24 hour duration tests to characterize and calibrate out diurnal effects. Bit-Error-Rate (BER) tests were performed to evaluate the end-to-end link BER performance of service through a TDRS K and L spacecraft. The TDRS M is planned to be launched in August 2017. This paper summarizes the results of the TDRS KL communications payload on-orbit performance verification and end-to-end service characterization and compares the results with the performance of the 2nd generation TDRS J. The paper also provides a high-level overview of an optical communications application that will augment the data rates supported by the Space Network.

Laser

Payload Performance of Third Generation TDRS and Future Services

NASA has accepted two of the 3rd generation Tracking and Data Relay Satellites, TDRS K, L, and M, designed and built by Boeing Defense, Space & Security (DSS). TDRS K, L, and M provide S-band Multiple Access (MA) service and S-band, Ku-band and Ka-band Single Access (SA) services to near Earth orbiting satellites. The TDRS KLM satellites offer improved services relative to the 1st generation TDRS spacecraft, such as: an enhanced MA service featuring increased EIRPs and G/T; and Ka-band SA capability which provides a 225 and 650 MHz return service (customer-to-TDRS direction) bandwidth and a 50 MHz forward service (TDRS-to-customer direction) bandwidth. MA services are provided through a 15 element forward phased array that forms up to two beams with onboard active beamforming and a 32 element return phased array supported by ground-based beamforming. SA services are provided through two 4.6m tri-band reflector antennas which support program track pointing and autotrack pointing. Prior to NASAs acceptance of the satellites, payload on-orbit testing was performed on each satellite to determine on-orbit compliance with design requirements. Performance parameters evaluated include: EIRP, G/T, antenna gain patterns, SA antenna autotrack performance, and radiometric tracking performance. On-orbit antenna calibration and pointing optimization was also performed on the MA and SA antennas including 24 hour duration tests to characterize and calibrate out diurnal effects. Bit-Error-Rate (BER) tests were performed to evaluate the end-to-end link BER performance of service through a TDRS K and L spacecraft. The TDRS M is planned to be launched in August 2017. This paper summarizes the results of the TDRS KL communications payload on-orbit performance verification and end-to-end service characterization and compares the results with the performance of the 2nd generation TDRS J. The paper also provides a high-level overview of an optical communications application that will augment the data rates supported by the Space Network.

RF

Adopting Internet Standards for Orbital Use

After a year of testing and demonstrating a Cisco mobile access router intended for terrestrial use onboard the low-Earth-orbiting UK-DMC satellite as part of a larger merged ground/space IP-based internetwork, we reflect on and discuss the benefits and drawbacks of integration and standards reuse for small satellite missions. Benefits include ease of operation and the ability to leverage existing systems and infrastructure designed for general use, as well as reuse of existing, known, and well-understood security and operational models. Drawbacks include cases where integration work was needed to bridge the gaps in assumptions between different systems, and where performance considerations outweighed the benefits of reuse of pre-existing file transfer protocols. We find similarities with the terrestrial IP networks whose technologies we have adopted and also some significant differences in operational models and assumptions that must be considered.

Wood, Lloyd

Estimating Tropical Cyclone Threats to Floating Rigs in the Gulf of Mexico

Offshore drilling operations in the Gulf of Mexico are particularly vulnerable during hurricane season. When a weather threat arises, a decision to evacuate the rig and/or move to a safe location may need to be made. Depending on the activities in progress at the time of the threat, securing the well, evacuating, and/or moving to a safe location can take a considerable amount of time. This transition time is called T-time. T-time is not only rig dependent, but also depends on the activity being performed at the time of the threat. For these reasons it is important to assess tropical cyclone threats and the time it takes for them to reach the rig location. The objective of this study is to use the available 50 years of past cyclone history to estimate cyclone threats at any location in the Gulf of Mexico. The cyclone threat is estimated based on the rig location as well as the start date and duration of the offshore activity. By threat, it is meant the likelihood that a specific location with an associated offshore activity would be exposed to an upcoming cyclone whose forecasted track cone and storm size lies within that location. Three representative rig locations in the Gulf of Mexico were selected as assessment sites to evaluate the threat of incoming cyclones for different T-times. To conduct this tropical cyclone study, an Excel spreadsheet tool was developed to automate the analysis of the tropical cyclone data from the Best Track Archive for Climate Stewardship (IBTrACS) Version 4. The spreadsheet tool allows the user to input any location (i.e., longitude and latitude) in the Gulf of Mexico and displays a list of historical cyclones that have passed within 150 nautical miles of that location during the activity period selected by the user. Also, the tool allows the user to input a T-time to assess the threat of cyclones that would not provide adequate time to secure the well, evacuate, and/or move to a safe location.

Risk

LightForce: An Update on Orbital Collision Avoidance Using Photon Pressure

We present an update on our research on collision avoidance using photon-pressure induced by ground-based lasers. In the past, we have shown the general feasibility of employing small orbit perturbations, induced by photon pressure from ground-based laser illumination, for collision avoidance in space. Possible applications would be protecting space assets from impacts with debris and stabilizing the orbital debris environment. Focusing on collision avoidance rather than de-orbit, the scheme avoids some of the security and liability implications of active debris removal, and requires less sophisticated hardware than laser ablation. In earlier research we concluded that one ground based system consisting of a 10 kW class laser, directed by a 1.5 m telescope with adaptive optics, could avoid a significant fraction of debris-debris collisions in low Earth orbit. This paper describes our recent efforts, which include refining our original analysis, employing higher fidelity simulations and performing experimental tracking tests. We investigate the efficacy of one or more laser ground stations for debris-debris collision avoidance and satellite protection using simulations to investigate multiple case studies. The approach includes modeling of laser beam propagation through the atmosphere, the debris environment (including actual trajectories and physical parameters), laser facility operations, and simulations of the resulting photon pressure. We also present the results of experimental laser debris tracking tests. These tests track potential targets of a first technical demonstration and quantify the achievable tracking performance.

Stupl, Jan

Development of a Methodology to Conduct Usability Evaluation for Hand Tools that May Reduce the Amount of Small Parts that are Dropped During Installation while Processing Space Flight Hardware

Foreign object debris (FOD) is an important concern while processing space flight hardware. FOD can be defined as "The debris that is left in or around flight hardware, where it could cause damage to that flight hardware," (United Space Alliance, 2000). Just one small screw left unintentionally in the wrong place could delay a launch schedule while it is retrieved, increase the cost of processing, or cause a potentially fatal accident. At this time, there is not a single solution to help reduce the number of dropped parts such as screws, bolts, nuts, and washers during installation. Most of the effort is currently focused on training employees and on capturing the parts once they are dropped. Advances in ergonomics and hand tool design suggest that a solution may be possible, in the form of specialty hand tools, which secure the small parts while they are being handled. To assist in the development of these new advances, a test methodology was developed to conduct a usability evaluation of hand tools, while performing tasks with risk of creating FOD. The methodology also includes hardware in the form of a testing board and the small parts that can be installed onto the board during a test. The usability of new hand tools was determined based on efficiency and the number of dropped parts. To validate the methodology, participants were tested while performing a task that is representative of the type of work that may be done when processing space flight hardware. Test participants installed small parts using their hands and two commercially available tools. The participants were from three groups: (1) students, (2) engineers / managers and (3) technicians. The test was conducted to evaluate the differences in performance when using the three installation methods, as well as the difference in performance of the three participant groups.

Miller, Darcy

Control and Non-Payload Communications (CNPC) Prototype Radio - Generation 2 Security Architecture Lab Test Report

NASA Glenn Research Center, in cooperation with Rockwell Collins, is working to develop a prototype Control and Non-Payload Communications (CNPC) radio platform as part of NASA Integrated Systems Research Program's (ISRP) Unmanned Aircraft Systems (UAS) Integration in the National Airspace System (NAS) project. A primary focus of the project is to work with the FAA and industry standards bodies to build and demonstrate a safe, secure, and efficient CNPC architecture that can be used by industry to evaluate the feasibility of deploying a system using these technologies in an operational capacity. GRC has been working in conjunction with these groups to assess threats, identify security requirements, and to develop a system of standards-based security controls that can be applied to the current GRC prototype CNPC architecture as a demonstration platform. The security controls were integrated into a lab test bed mock-up of the Mobile IPv6 architecture currently being used for NASA flight testing, and a series of network tests were conducted to evaluate the security overhead of the controls compared to the baseline CNPC link without any security. The aim of testing was to evaluate the performance impact of the additional security control overhead when added to the Mobile IPv6 architecture in various modes of operation. The statistics collected included packet captures at points along the path to gauge packet size as the sample data traversed the CNPC network, round trip latency, jitter, and throughput. The effort involved a series of tests of the baseline link, a link with Robust Header Compression (ROHC) and without security controls, a link with security controls and without ROHC, and finally a link with both ROHC and security controls enabled. The effort demonstrated that ROHC is both desirable and necessary to offset the additional expected overhead of applying security controls to the CNPC link.

Communication Networks

Ensuring Flexibility and Security in SDN-Based Spacecraft Communication Networks Through Risk Assessment

Software-defined networking (SDN) has enabled elastic networking and resource distribution in cloud computing. The centralization and separation of the Control Plane also offers a high degree of network configurability and management, which can be used to mitigate and manage threats to the network. Space communication networks have historically been restricted and circuit switching in these networks has been a manual process. This study evaluates the potential role of SDN in space communication networks from a networking security standpoint. The evaluation covers the networking security needs of spacecraft missions and their associated assets. The results from the evaluation lead to a risk assessment that identifies vulnerabilities in an SDN-based communications architecture. Security challenges introduced into the network from integrating SDN are also considered. A risk register summarizes the severity of the attack outcomes, as well as occurrence likelihood. The study identifies Denial-of-Service (DoS) attacks as a new threat (presently unmitigated by existing security controls) that would be prevalent in an SDN-based space communication environment. A Mininet-based emulation testbed is built to demonstrate the susceptibility of spacecraft flight software to a flooding DoS attack when on an interconnected SDN-managed network. This type of attack would be highly consequential to mission assets, and therefore SDN-based space communications would need to be resilient to such attacks. Future work will need to be performed to fully characterize DoS attack methods that can apply to the space communication scenario, as well as to devise a comprehensive DoS-resilient solution.

Baker, Dylan Z.

In-Time Non-Participant Casualty Risk Assessment to Support Onboard Decision Making for Autonomous Unmanned Aircraft

Numerous operational paradigms, technologies, and missions are emerging as newcomers to the National Airspace System (NAS) develop small Unmanned Aircraft Systems (sUAS), personal air vehicles and other Urban Air Mobility (UAM) concepts. As the list of applications expands, maintaining the safety of the current airspace system remains one of the core concerns preventing widespread commercial implementation of these concepts. Further, the risks associated with unmanned aircraft operations themselves have to be recognized and mitigated in a timely manner. Safety-critical risks include, but are not limited to, flight outside of approved airspace, unsafe proximity to people or property, critical system failures, loss-of control, and cyber-security related risks. Instead of reacting to accidents, a set of predictive and data-driven risk monitoring, assessment, and mitigation capabilities are envisioned to help capture and eliminate hazards as these systems become operational. NASA’s System-wide Safety project is performing R&D on such a safety assurance concept. As part of this concept, this paper describes an architecture that continuously monitors a diverse set of onboard and ground-based sources to estimate and predict non-participant casualty risk during flight. Timely identification of the changing nature of this risk can inform decision making processes to mitigate current and impending situations.

Ancel, Ersin

Space-based Science Operations Grid Prototype

Grid technology is the up and coming technology that is enabling widely disparate services to be offered to users that is very economical, easy to use and not available on a wide basis. Under the Grid concept disparate organizations generally defined as "virtual organizations" can share services i.e. sharing discipline specific computer applications, required to accomplish the specific scientific and engineering organizational goals and objectives. Grids are emerging as the new technology of the future. Grid technology has been enabled by the evolution of increasingly high speed networking. Without the evolution of high speed networking Grid technology would not have emerged. NASA/Marshall Space Flight Center's (MSFC) Flight Projects Directorate, Ground Systems Department is developing a Space-based Science Operations Grid prototype to provide to scientists and engineers the tools necessary to operate space-based science payloads/experiments and for scientists to conduct public and educational outreach. In addition Grid technology can provide new services not currently available to users. These services include mission voice and video, application sharing, telemetry management and display, payload and experiment commanding, data mining, high order data processing, discipline specific application sharing and data storage, all from a single grid portal. The Prototype will provide most of these services in a first step demonstration of integrated Grid and space-based science operations technologies. It will initially be based on the International Space Station science operational services located at the Payload Operations Integration Center at MSFC, but can be applied to many NASA projects including free flying satellites and future projects. The Prototype will use the Internet2 Abilene Research and Education Network that is currently a 10 Gb backbone network to reach the University of Alabama at Huntsville and several other, as yet unidentified, Space Station based science experimenters. There is an international aspect to the Grid involving the America's Pathway (AMPath) network, the Chilean REUNA Research and Education Network and the University of Chile in Santiago that will further demonstrate how extensive these services can be used. From the user's perspective, the Prototype will provide a single interface and logon to these varied services without the complexity of knowing the where's and how's of each service. There is a separate and deliberate emphasis on security. Security will be addressed by specifically outlining the different approaches and tools used. Grid technology, unlike the Internet, is being designed with security in mind. In addition we will show the locations, configurations and network paths associated with each service and virtual organization. We will discuss the separate virtual organizations that we define for the varied user communities. These will include certain, as yet undetermined, space-based science functions and/or processes and will include specific virtual organizations required for public and educational outreach and science and engineering collaboration. We will also discuss the Grid Prototype performance and the potential for further Grid applications both space-based and ground based projects and processes. In this paper and presentation we will detail each service and how they are integrated using Grid

Bradford, Robert N.

Identification of Security related Bug Reports via Text Mining using Supervised and Unsupervised Classification

This paper is focused on automated classification of software bug reports to security and non-security related, using both supervised and unsupervised approaches. For both approaches, three types of feature vectors are used. For supervised learning, we experiment with multiple learning algorithms and training sets with different sizes. Furthermore, we propose a novel unsupervised approach based on anomaly detection. The evaluated is based on three NASA datasets. The results show that supervised classification is affected more by the learning algorithms than by feature vectors and using only 25% of the data for training provides as good results as if 90% of data are used for training. Both supervised and unsupervised learning can be used for identification of security bug reports; the former slightly outperforms the latter at the expense of labeling the testing set. In general, the performance differs across datasets, mainly due to the different amounts of security related information.

Goseva-Popstojanova, Katerina

Entry, Descent, and Landing Analysis for the OSIRIS-REx Sample Return Capsule

The Origins, Spectral Interpretation, Resource Identification, and Security – Regolith Explorer (OSIRIS-REx) sample return capsule (SRC) returned to Earth on September 24, 2023, safely landing in the Utah Test and Training Range (UTTR). To ensure a safe and successful landing, a pair of high-fidelity EDL simulations, based on the Program to Optimize Simulated Trajectories (POST) architecture, were used to regularly assess the latest orbit determination (OD) solution from the navigation team, making predictions on Entry, Descent, and Landing (EDL) performance and SRC landing location. The results from these analyses fed into the decision processes for the final trajectory correction maneuvers (TCM’s) and SRC release. The models and methods of analysis will be discussed and a comparison of the final pre-entry landing prediction against the observed landing location will be presented along with an assessment of the best estimates of day-of-entry environmental conditions.

Scott R Francis