Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “encryption”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Additively Manufactured Tamper Evident Container

Los Alamos National Laboratory has developed a revolutionary and reliable new tamper evident container (TEC) to monitor and protect the health, security, and distribution of high-value assets, technological advancements, products, materials and more that are critical to the operations of businesses and government organizations. Unlike traditional tamper evident seals, the entire TEC serves as a seal, with encrypted on-board electronics able to continuously monitor and log structural health data including but not limited to force, temperature, pressure, humidity, orientation, radiation, acceleration, or vibration as needed. Analog and encrypted digital boards safely stored inside the TEC permanently record the complete integrity history of the protected items and have the ability to alert the TEC owners or take immediate defensive actions should a disruptive or tamper event take place.

36 MATERIALS SCIENCE↗

Security Enhancements for Distributed Energy Resource Systems Interconnected with Distribution Networks: Final Technical Report

The revised IEEE 1547 Standard defines new complex communication-adjustable voltage and frequency regulation and ride-through characteristics, while maintaining the general antiislanding requirement for unintentional islanding situations. Unintentional islanding is prohibited while intentional islanding is specifically allowed, thus effectively enabling microgrid operation mode. Further, IEEE 1547-2018 Standard introduces new requirements in terms of interoperability so that the DER plant/circuit segments may be seamlessly integrated with the utility networks but at the same time become vulnerable to a cyber-attack. Traditional cybersecurity measures including encryption, authentication and role-based access control may not be fully implementable to all communication protocols specified in the IEEE 1547 Standard. Therefore, in this project we have identified, researched, implemented and tested several cyberphysical approaches that rely mostly on the behavior of the DER circuit and may help with validating the incoming command and control action potentially coming through an insecure communications channel. Additionally, we have built semantic models and communications profiles for DER facilities and have implemented lightweight IEC 61850 based publisher-subscriber GOOSE messaging mechanism, with security extensions in terms of authentication and encryption. The project proposed information models for integration into UCA OpenFMB 2.0 profiles focusing on grid code compliance.

24 POWER TRANSMISSION AND DISTRIBUTION↗

The Integration of The Cloudflare WAF

HTTP Strict Transport Security (HSTS) is a standard that ensures website visitor’s traffic is always sent using HTTPS ensuring that all traffic is protected during transit. This initiative was adopted in 2012 by the IETF and has grown in popularity all around the world. Because the traffic is encrypted with TLS/SSL, it can be used by attackers to bypass various cybersecurity capabilities such as a site firewall. To address this lack of visibility into encrypted traffic in motion, the CST at Fermilab acquired the Cloudflare Web Application Firewall (WAF). To help in the implementation and integration of the Cloudflare WAF, I was directed to learn about and aid in this process. This has been a profound learning experience into the on-goings of project management, web application firewalls, collaboration, and networking.

Blum, Ethan T.↗

Precursor Analysis Report: Conti Ransomware Attack on the Health Service Executive of Ireland 2021

The Conti Ransomware Attack on the Health Service Executive (HSE) of Ireland 2021 Precursor Analysis Report leverages publicly available information about the attack and catalogs anomalous observables for each technique employed by the adversary. This analysis is based upon the methodology of the Cybersecurity for the Operational Technology Environment (CyOTE) program. The HSE provides public healthcare corporate services and operational services throughout Ireland, with critical functions including the acute national ambulance service, acute hospital service, and community healthcare service. On 14 May 2021, Conti ransomware encrypted 80 percent of the HSE’s Information Technology (IT) infrastructure across corporate, hospital, community, and electronic health record services. Conti is a ransomware-as-a-service operation that encrypts local files, uses double extortion against victims, and is facilitated by many intrusion tools. The attack forced the HSE to shut down its entire IT infrastructure to contain the ransomware, forcing employees to revert to pen and paper recordkeeping and leading to the cancellation of many appointments and procedures. The adversary also exfiltrated 700 GB of data, compromising the confidentiality of patients’ protected health information. Had the adversary targeted the COVID-19 cloud systems or operational technology assets, such as Internet of Medical Things medical devices or smart building management systems, the impact of the attack would almost certainly have been far more severe. Researchers and analysts identified 21 unique techniques (used in a sequence of 23 steps) likely utilized during the attack with a total of 1,185 observables using MITRE ATT&CK® for Industrial Control Systems. The CyOTE program assesses observables accompanying techniques used prior to the triggering event to identify opportunities to detect malicious activity. If observables accompanying the attack techniques are perceived and investigated prior to the triggering event, earlier comprehension of malicious activity can take place. Twenty-one of the identified techniques used during the attack on the HSE were precursors to the triggering event. Analysis identified 1,086 observables associated with these precursor techniques, 850 of which were assessed to have an increased likelihood of being perceived in the 57 days preceding the triggering event. The response and comprehension time could have been reduced if the observables had been identified earlier. The information gathered in this report contributes to a library of observables tied to a repository of artifacts, data sources, and technique detection references for practitioners and developers to support the comprehension of indicators of attack. Asset owners and operators can use these products if they experience similar observables or to prepare for comparable scenarios.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

Privacy-Preserving Transactive Energy System

In this paper, the privacy issue of recently proposed transactive energy systems for electric power systems is studied for the first time. It is identified that the private information of individual market participants is subject to the risk of leakage during their market-based interaction. In order to protect their privacy, a homomorphic encryption-based approach is developed to achieve the privacy preservation with the Paillier encryption scheme. The proposed privacy-perserving design is then demonstrated on a transactive energy system that coordinates and controls residential air conditioners to manage the feeder congestion. The simulation results confirm the effectiveness of the proposed design in protecting the privacy of individual market participants without affecting the overall system performance. Future work on the proposed design is also suggested.

Lu, Yang↗

Implementation notes on bdes(1)

This note describes the implementation of bdes, the file encryption program being distributed in the 4.4 release of the Berkeley Software Distribution. It implements all modes of the Data Encryption Standard program.

Bishop, Matt↗

Timing in private digital telecommunication networks

For proper operation of today's large digital private networks, high quality synchronization must be achieved. A general telecommunication performance objective is to maintain long-term frequency accuracy of ten parts per trillion at all synchronous digital equipment in the network. Many times, however, this is not achieved in private networks. Low quality clocks, errored transmission facilities, and incorrectly designed synchronization plans are often cause for poor performance. It is shown that properly-designed private networks can operate with long term frequency averages between ten parts per trillion to ten parts per million. These performance levels can adversely impact customer applications. The most demanding applications are digital and voice band data, encrypted voice, facsimile, and video. In a typical private network operating at 0.01 parts per million, the user would experience reduced data throughput, dropped encrypted calls, unreadable facsimile pages, or interrupted video transmission dozens of times per day. The major contribution to poor private network synchronization performance is the interaction of Customer Premises Equipment (CPE) clocks and the network facilities used to distribute timing. The performance of typical CPE clocks and facilities, and their impact on customer applications, are discussed. CPE clock performance issues, along with private network architectural constraints, make synchronization planning extremely difficult. Planning is usually costly and requires specialized expertise.

Abate, J. E.↗

Digital camera with apparatus for authentication of images produced from an image file

A digital camera equipped with a processor for authentication of images produced from an image file taken by the digital camera is provided. The digital camera processor has embedded therein a private key unique to it, and the camera housing has a public key that is so uniquely based upon the private key that digital data encrypted with the private key by the processor may be decrypted using the public key. The digital camera processor comprises means for calculating a hash of the image file using a predetermined algorithm, and second means for encrypting the image hash with the private key, thereby producing a digital signature. The image file and the digital signature are stored in suitable recording means so they will be available together. Apparatus for authenticating at any time the image file as being free of any alteration uses the public key for decrypting the digital signature, thereby deriving a secure image hash identical to the image hash produced by the digital camera and used to produce the digital signature. The apparatus calculates from the image file an image hash using the same algorithm as before. By comparing this last image hash with the secure image hash, authenticity of the image file is determined if they match, since even one bit change in the image hash will cause the image hash to be totally different from the secure hash.

Friedman, Gary L.↗

Time and position accuracy using codeless GPS

The Global Positioning System has allowed scientists and engineers to make measurements having accuracy far beyond the original 15 meter goal of the system. Using global networks of P-Code capable receivers and extensive post-processing, geodesists have achieved baseline precision of a few parts per billion, and clock offsets have been measured at the nanosecond level over intercontinental distances. A cloud hangs over this picture, however. The Department of Defense plans to encrypt the P-Code (called Anti-Spoofing, or AS) in the fall of 1993. After this event, geodetic and time measurements will have to be made using codeless GPS receivers. However, there appears to be a silver lining to the cloud. In response to the anticipated encryption of the P-Code, the geodetic and GPS receiver community has developed some remarkably effective means of coping with AS without classified information. We will discuss various codeless techniques currently available and the data noise resulting from each. We will review some geodetic results obtained using only codeless data, and discuss the implications for time measurements. Finally, we will present the status of GPS research at JPL in relation to codeless clock measurements.

Dunn, C. E.↗

Signal-processing theory for the TurboRogue receiver

Signal-processing theory for the TurboRogue receiver is presented. The signal form is traced from its formation at the GPS satellite, to the receiver antenna, and then through the various stages of the receiver, including extraction of phase and delay. The analysis treats the effects of ionosphere, troposphere, signal quantization, receiver components, and system noise, covering processing in both the 'code mode' when the P code is not encrypted and in the 'P-codeless mode' when the P code is encrypted. As a possible future improvement to the current analog front end, an example of a highly digital front end is analyzed.

Thomas, J. B.↗

Digital Camera with Apparatus for Authentication of Images Produced from an Image File

A digital camera equipped with a processor for authentication of images produced from an image file taken by the digital camera is provided. The digital camera processor has embedded therein a private key unique to it, and the camera housing has a public key that is so uniquely related to the private key that digital data encrypted with the private key may be decrypted using the public key. The digital camera processor comprises means for calculating a hash of the image file using a predetermined algorithm, and second means for encrypting the image hash with the private key, thereby producing a digital signature. The image file and the digital signature are stored in suitable recording means so they will be available together. Apparatus for authenticating the image file as being free of any alteration uses the public key for decrypting the digital signature, thereby deriving a secure image hash identical to the image hash produced by the digital camera and used to produce the digital signature. The authenticating apparatus calculates from the image file an image hash using the same algorithm as before. By comparing this last image hash with the secure image hash, authenticity of the image file is determined if they match. Other techniques to address time-honored methods of deception, such as attaching false captions or inducing forced perspectives, are included.

Friedman, Gary L.↗

Secure Web-based Ground System User Interfaces over the Open Internet

A prototype has been developed which makes use of commercially available products in conjunction with the Java programming language to provide a secure user interface for command and control over the open Internet. This paper reports successful demonstration of: (1) Security over the Internet, including encryption and certification; (2) Integration of Java applets with a COTS command and control product; (3) Remote spacecraft commanding using the Internet. The Java-based Spacecraft Web Interface to Telemetry and Command Handling (Jswitch) ground system prototype provides these capabilities. This activity demonstrates the use and integration of current technologies to enable a spacecraft engineer or flight operator to monitor and control a spacecraft from a user interface communicating over the open Internet using standard World Wide Web (WWW) protocols and commercial off-the-shelf (COTS) products. The core command and control functions are provided by the COTS Epoch 2000 product. The standard WWW tools and browsers are used in conjunction with the Java programming technology. Security is provided with the current encryption and certification technology. This system prototype is a step in the direction of giving scientist and flight operators Web-based access to instrument, payload, and spacecraft data.

Langston, James H.↗

An On-line Technology Information System (OTIS) for Advanced Life Support

OTIS is an on-line communication platform designed for smooth flow of technology information between advanced life support (ALS) technology developers, researchers, system analysts, and managers. With pathways for efficient transfer of information, several improvements in the ALS Program will result. With OTIS, it will be possible to provide programmatic information for technology developers and researchers, technical information for analysts, and managerial decision support. OTIS is a platform that enables the effective research, development, and delivery of complex systems for life support. An electronic data collection form has been developed for the solid waste element, drafted by the Solid Waste Working Group. Forms for other elements (air revitalization, water recovery, food processing, biomass production and thermal control) will also be developed, based on lessons learned from the development of the solid waste form. All forms will be developed by consultation with other working groups, comprised of experts in the area of interest. Forms will be converted to an on-line data collection interface that technology developers will use to transfer information into OTIS. Funded technology developers will log in to OTIS annually to complete the element- specific forms for their technology. The type and amount of information requested expands as the technology readiness level (TRL) increases. The completed forms will feed into a regularly updated and maintained database that will store technology information and allow for database searching. To ensure confidentiality of proprietary information, security permissions will be customized for each user. Principal investigators of a project will be able to designate certain data as proprietary and only technical monitors of a task, ALS Management, and the principal investigator will have the ability to view this information. The typical OTIS user will be able to read all non-proprietary information about all projects.Interaction with the database will occur over encrypted connections, and data will be stored on the server in an encrypted form. Implementation of OTIS will initiate a community-accessible repository of technology development information. With OTIS, ALS element leads and managers will be able to carry out informed technology selection for programmatic decisions. OTIS will also allow analysts to make accurate evaluations of technology options. Additionally, the range and specificity of information solicited will help educate technology developers of program needs. With augmentation, OTIS reporting is capable of replacing the current fiscal year-end reporting process. Overall, the system will enable more informed R&TD decisions and more rapid attainment of ALS Program goals.

Levri, Julie A.↗

All about Eve: Secret Sharing using Quantum Effects

This document discusses the nature of light (including classical light and photons), encryption, quantum key distribution (QKD), light polarization and beamsplitters and their application to information communication. A quantum of light represents the smallest possible subdivision of radiant energy (light) and is called a photon. The QKD key generation sequence is outlined including the receiver broadcasting the initial signal indicating reception availability, timing pulses from the sender to provide reference for gated detection of photons, the sender generating photons through random polarization while the receiver detects photons with random polarization and communicating via data link to mutually establish random keys. The QKD network vision includes inter-SATCOM, point-to-point Gnd Fiber and SATCOM-fiber nodes. QKD offers an unconditionally secure method of exchanging encryption keys. Ongoing research will focus on how to increase the key generation rate.

no cloning theorem↗

Enhanced Flight Termination System (EFTS): Flight Demonstration and Results

The Enhanced Flight Termination System (EFTS) program was initiated and propelled due to the inadvertent terminations of Global Hawk and the Strategic Target System and the NASA Inspector General's assessment letter and recommendations regarding the exploration of low-cost, lightweight space COMSEC for FTS. Additionally, the standard analog and high alphabet systems most commonly used in FTS are secure, but not encrypted. A study group was initiated to select and document a robust, affordable, reliable technology that provides encrypted FTS capability. A flight demonstration was conducted to gain experience using EFTS in an operational environment, provide confidence in the use of the EFTS components, integrate EFTS into an existing range infrastructure to demonstrate the scalability of system components, to provide a command controller that generated the EFTS waveform using an existing range infrastructure, and to provide a report documenting the results of the demonstration. The primary goal of the demonstration was to obtain operational experience with EFTS. Areas of operational experience include: mission planning, pre-flight configuration and testing, mission monitoring and recording, vehicle termination, developing mission procedures. and post mission data reduction and other post mission activities. An Advanced Medium-Range Air-to-Air Missile (AMRAAM) was selected to support the EFTS demonstration due to interest in future use of EFTS by the AMRAAM program, familiarity of EFTS by range personnel, and the availability of existing operational environment to support EFTS testing with available program funding. For demonstration purposes, the AMRAAM was successfully terminated using an EFTS receiver and successfully demonstrating EFTS. The EFTS monitoring software with spectrum analyzer and digital graphical display of aircraft, missile, and target were also demonstrated.

Tow, David↗

System for Secure Integration of Aviation Data

The Aviation Data Integration System (ADIS) of Ames Research Center has been established to promote analysis of aviation data by airlines and other interested users for purposes of enhancing the quality (especially safety) of flight operations. The ADIS is a system of computer hardware and software for collecting, integrating, and disseminating aviation data pertaining to flights and specified flight events that involve one or more airline(s). The ADIS is secure in the sense that care is taken to ensure the integrity of sources of collected data and to verify the authorizations of requesters to receive data. Most importantly, the ADIS removes a disincentive to collection and exchange of useful data by providing for automatic removal of information that could be used to identify specific flights and crewmembers. Such information, denoted sensitive information, includes flight data (here signifying data collected by sensors aboard an aircraft during flight), weather data for a specified route on a specified date, date and time, and any other information traceable to a specific flight. The removal of information that could be used to perform such tracing is called "deidentification." Airlines are often reluctant to keep flight data in identifiable form because of concerns about loss of anonymity. Hence, one of the things needed to promote retention and analysis of aviation data is an automated means of de-identification of archived flight data to enable integration of flight data with non-flight aviation data while preserving anonymity. Preferably, such an automated means would enable end users of the data to continue to use pre-existing data-analysis software to identify anomalies in flight data without identifying a specific anomalous flight. It would then also be possible to perform statistical analyses of integrated data. These needs are satisfied by the ADIS, which enables an end user to request aviation data associated with de-identified flight data. The ADIS includes client software integrated with other software running on flight-operations quality-assurance (FOQA) computers for purposes of analyzing data to study specified types of events or exceedences (departures of flight parameters from normal ranges). In addition to ADIS client software, ADIS includes server hardware and software that provide services to the ADIS clients via the Internet (see figure). The ADIS server receives and integrates flight and non-flight data pertaining to flights from multiple sources. The server accepts data updates from authorized sources only and responds to requests from authorized users only. In order to satisfy security requirements established by the airlines, (1) an ADIS client must not be accessible from the Internet by an unauthorized user and (2) non-flight data as airport terminal information system (ATIS) and weather data must be displayed without any identifying flight information. ADIS hardware and software architecture as well as encryption and data display scheme are designed to meet these requirements. When a user requests one or more selected aviation data characteristics associated with an event (e.g., a collision, near miss, equipment malfunction, or exceedence), the ADIS client augments the request with date and time information from encrypted files and submits the augmented request to the server. Once the user s authorization has been verified, the server returns the requested information in de-identified form.

Kulkarni, Deepak↗

The Trustworthy Digital Camera: Restoring Credibility to the Photographic Image

The increasing sophistication of computers has made digital manipulation of photographic images incredibly easy to perform and, as time goes on, increasingly difficult to detect. The proposed device is a new type of digital camera whose output can be certified as being unretouched, and can restore the credibility that the photographic image once enjoyed. The Trustworthy Digital Camera employs public key encryption techniques at the system level, and produces an encrypted digital signature and a standard-format digital image file each time a picture is taken. Although digitally retouching or altering these image files would still be possible, doing so will cause a mismatch with the verifying signature, proving that the image is not an untouched original...

Friedman, Gary L.↗

Continuous Test and Transition Infrastructure for Quantum Networking for Science Complex

We propose a network architecture with a separate quantum dataplane and a conventional control plane: (a) Quantum Data Plane: The Quantum Data plane consists of links of dark fibers connecting quantum switches and repeaters, which in turn, connect to quantum computers, memory and sensors. Since the current reach is limited to local areas, it will begin as a collection of site networks at laboratories, (b) Conventional Control Plane: The Control plane provides management access to quantum devices for configuration and provisioning via control nodes with firewall and encryption capabilities. Continuous Test and Transition Infrastructure: We propose an infrastructure with a control plane connecting multiple sites via encrypted tunnels over conventional networks consisting of the following: (a) Site Quantum Networks: Individual site networks supported by their fiber plants connect laboratories that house and connect to their quantum devices for testing and interoperability.(b) Site Control Planes: Sites are connected over individual control planes with control hosts with Software Defined Networking capabilities, which can be peered with other networks via ESnet.(c) Progressive Expansion: Initially, sites will develop individual data planes with their specific quantum devices and fiber connections, and mechanisms to interface with conventional networks. They progressively expand and interconnect, under a wide-area ecosystem of peered control planes for device testing, interoperability development and roll off into production environments.

Rao, Nageswara S.↗