Engineering PapersSearch

SEARCH · Engineering Papers

Results for “information protection”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Autonomous Information Unit for Fine-Grain Data Access Control and Information Protection in a Net-Centric System

As communication and networking technologies advance, networks will become highly complex and heterogeneous, interconnecting different network domains. There is a need to provide user authentication and data protection in order to further facilitate critical mission operations, especially in the tactical and mission-critical net-centric networking environment. The Autonomous Information Unit (AIU) technology was designed to provide the fine-grain data access and user control in a net-centric system-testing environment to meet these objectives. The AIU is a fundamental capability designed to enable fine-grain data access and user control in the cross-domain networking environments, where an AIU is composed of the mission data, metadata, and policy. An AIU provides a mechanism to establish trust among deployed AIUs based on recombining shared secrets, authentication and verify users with a username, X.509 certificate, enclave information, and classification level. AIU achieves data protection through (1) splitting data into multiple information pieces using the Shamir's secret sharing algorithm, (2) encrypting each individual information piece using military-grade AES-256 encryption, and (3) randomizing the position of the encrypted data based on the unbiased and memory efficient in-place Fisher-Yates shuffle method. Therefore, it becomes virtually impossible for attackers to compromise data since attackers need to obtain all distributed information as well as the encryption key and the random seeds to properly arrange the data. In addition, since policy can be associated with data in the AIU, different user access and data control strategies can be included. The AIU technology can greatly enhance information assurance and security management in the bandwidth-limited and ad hoc net-centric environments. In addition, AIU technology can be applicable to general complex network domains and applications where distributed user authentication and data protection are necessary. AIU achieves fine-grain data access and user control, reducing the security risk significantly, simplifying the complexity of various security operations, and providing the high information assurance across different network domains.

Chow, Edward T.

Space Shuttle security policies and programs

The Space Shuttle vehicle consists of the orbiter, external tank, and two solid rocket boosters. In dealing with security two major protective categories are considered, taking into account resource protection and information protection. A review is provided of four basic programs which have to be satisfied. Aspects of science and technology transfer are discussed. The restrictions for the transfer of science and technology information are covered under various NASA Management Instructions (NMI's). There were two major events which influenced the protection of sensitive and private information on the Space Shuttle program. The first event was a manned space flight accident, while the second was the enactment of a congressional bill to establish the rights of privacy. Attention is also given to national resource protection and national defense classified operations.

Keith, E. L.

Autonomous Information Unit: Why Making Data Smart Can also Make Data Secured?

In this paper, we introduce a new fine-grain distributed information protection mechanism which can self-protect, self-discover, self-organize, and self-manage. In our approach, we decompose data into smaller pieces and provide individualized protection. We also provide a policy control mechanism to allow 'smart' access control and context based re-assembly of the decomposed data. By combining smart policy with individually protected data, we are able to provide better protection of sensitive information and achieve more flexible access during emergency conditions. As a result, this new fine-grain protection mechanism can enable us to achieve better solutions for problems such as distributed information protection and identity theft.

data security

IT Challenges for Space Medicine or How do We Protect Medical Information and Still Get Useful Work Done?

Space Medicine provides healthcare services of various types for astronauts throughout their lifetime starting from the time they are selected as astronauts. IT challenges include: protection of private medical information, access from locations both inside and outside NASA, nearly 24x7 access, access during disasters, international partner access, data archiving, off-region backup, secure communication of medical data to people outside the NASA system (e.g. expert consultants), efficient movement of medical record information between locations, search and retrieval of relevant information, and providing all of these services/capabilities within a limited budget. In Space Medicine, we have provided for these in various ways: limit the amount of private medical information stored locally, utilize encryption mechanisms that the international partners can also use, utilize 2-factor authentication, virtualize servers, employ concept-based search, and use of standardized terminologies (SNOMED) and messaging (HL7).

Johnson-Throop, Kathy A.

Informing Planetary Protection Policies for the Future Exploration of Ceres: State of Understanding after the Dawn Mission

We review the current state of understanding of Ceres as it relates to planetary protection policy for future landed missions, including for sample return, to the dwarf planet. The Dawn mission found Ceres to be an intriguing target for a mission, with evidence for the presence of regional, possibly extensive liquid at depth, and local expressions of recent and potentially ongoing activity. The Dawn mission also found a high abundance of carbon in the regolith, interpreted as a mix of carbonates and amorphous carbon, as well as locally high concentrations of organic matter. Key findings from this review are as follows: (1) outside of the region of Occator crater, Ceres shows no geological evidence for conduits from the surface to the interior; and (2) considering the biological potential of Ceres’ deep interior, a surface sample return mission should be considered Category V restricted, unless it can be demonstrated that evaporites sourced from Ceres’ deep brine region, and recently exposed in Occator crater, have not been scattered to the rest of Ceres’ surface; in that case, the probability of returning an unsterilized particle to an acceptably low value is to be determined by a future study. Key Words: Ceres—Planetary protection—Brines—Future missions.

Julie Castillo-Rogez

Considerations for an earth physics information-management service.

In a preliminary investigation into the feasibility of establishing a data center for earth physics, 12 disciplines were considered for inclusion. Estimation of the size of the data base for each indicated a need for storage of approximately 10 to the 10th power characters. The computer-based system deemed most worthy of further investigation was the interactive concept with remote-terminal access. Users are divided into three classes according to how they would access information: with no terminal, with an interactive terminal, and with a multidevice terminal. All these users can be served by the same center without any particular difficulty, but the real benefactor is the user with an interactive terminal, because he can compile, debug, and run programs in one continuous session. Final points stressed are multiprogramming for dynamic resource sharing, hardware modularity for future expansion, and information protection for such a large community of users. It is concluded that a survey should be conducted to gather more information from the potential users of such a system, and that a pilot project should be developed at some location where both earth-physics research and data-processing capabilities already exist.

Martin, R. W.

NASA Tech Briefs, April 2012

Topics include: Computational Ghost Imaging for Remote Sensing; Digital Architecture for a Trace Gas Sensor Platform; Dispersed Fringe Sensing Analysis - DFSA; Indium Tin Oxide Resistor-Based Nitric Oxide Microsensors; Gas Composition Sensing Using Carbon Nanotube Arrays; Sensor for Boundary Shear Stress in Fluid Flow; Model-Based Method for Sensor Validation; Qualification of Engineering Camera for Long-Duration Deep Space Missions; Remotely Powered Reconfigurable Receiver for Extreme Environment Sensing Platforms; Bump Bonding Using Metal-Coated Carbon Nanotubes; In Situ Mosaic Brightness Correction; Simplex GPS and InSAR Inversion Software; Virtual Machine Language 2.1; Multi-Scale Three-Dimensional Variational Data Assimilation System for Coastal Ocean Prediction; Pandora Operation and Analysis Software; Fabrication of a Cryogenic Bias Filter for Ultrasensitive Focal Plane; Processing of Nanosensors Using a Sacrificial Template Approach; High-Temperature Shape Memory Polymers; Modular Flooring System; Non-Toxic, Low-Freezing, Drop-In Replacement Heat Transfer Fluids; Materials That Enhance Efficiency and Radiation Resistance of Solar Cells; Low-Cost, Rugged High-Vacuum System; Static Gas-Charging Plug; Floating Oil-Spill Containment Device; Stemless Ball Valve; Improving Balance Function Using Low Levels of Electrical Stimulation of the Balance Organs; Oxygen-Methane Thruster; Lunar Navigation Determination System - LaNDS; Launch Method for Kites in Low-Wind or No-Wind Conditions; Supercritical CO2 Cleaning System for Planetary Protection and Contamination Control Applications; Design and Performance of a Wideband Radio Telescope; Finite Element Models for Electron Beam Freeform Fabrication Process Autonomous Information Unit for Fine-Grain Data Access Control and Information Protection in a Net-Centric System; Vehicle Detection for RCTA/ANS (Autonomous Navigation System); Image Mapping and Visual Attention on the Sensory Ego-Sphere; HyDE Framework for Stochastic and Hybrid Model-Based Diagnosis; and IMAGESEER - IMAGEs for Education and Research.

Source record

Scalable Asset Discovery, Vulnerability Scanning, and Penetration Testing for Remote Sites and Wireless Spectrums Utilizing an Embedded Linux Plug - PwniPlug and the Raspberry Pi B+ as a Sample Pen Test

All devices attached to the NASA KSC network are subject to security vulnerability scanning and/or penetration testing. In today's changing environment, vulnerable and/or unprotected systems can easily be overlooked. Systems that are not properly managed can become a potential threat to the operational integrity of our systems and networks. This includes all NASA (internal and external) information systems within NASA KSC Internet Protocol (IP) address space, and NASA KSC facilities. The Office of the Chief Information Officer (OCIO) recommends that all NASA Centers and information systems be subject to penetration testing on a regular interval in accordance with the guidelines identified by the National Institute of Standards and Technology (NIST). (ITS-HBK-2810.04-02A) Protecting information and equipment at NASA is an area of increasing concern. In addition to the CPU's on the network; Supervisory, Control and Data Acquisition (SCADA) systems are especially vulnerable because these systems have lacked standards, use embedded controllers with little computational power and informal software, are connected to physical processes, have few operators, and are increasingly also being connected to corporate networks. The scope of work is comprised of several individual components which together build upon previous work by Drew Branch, NASA KSC Intern. The Pwn Plug is the selected COTS (Commercial-Off-The-Shelf) device chosen to test simplification of mandatory IT Security tasks. The device will be utilized to provide services to NASA KSC and enable an assessment of infrastructure soundness and regulatory compliance in an efficient, economical, and business responsive manner. The Pwn Plug is designed as a pen testing appliance which provides a hardware platform that can support commercial penetration testing efforts at significantly reduced costs. The expected outcomes are: 1) External Penetration Testing, 2) Social Engineering, 3) Procedural Documentation, 4) Recommended Remediation Action Plan, 5) System Retest & Remediation Attestation and 6) Final Reports, out briefing and Presentation. Due to physical and material constraints beyond intern and mentor control, the project was redefined as a working pen-test scenario. Limitations of lab availability and tools dictated an academic exercise. This report was developed within the scenario guidelines suggested by the project mentor. The guidelines were to be creative in developing a Pen Test program for a client.

Penetration Testing

Optimizing a detection system for fissile material in nuclear disarmament verification

In arms control treaties, verification plays a crucial role in detecting non-compliance, deterring future violations, and building trust between state parties. Neutron interrogation that induces fission reactions in fissile isotopes and measures the resulting fission neutrons, could be employed for this purpose. This study aims to develop a system which can determine the presence of fissile material while intrinsically protecting information. In this paper, we focus on optimizing the system for discriminating between an enriched uranium block from a depleted uranium (DU) block. The system was built and we report on benchmark measurements with DU and 16% enriched uranium blocks. Furthermore, the Excalibur (Experiment for Calibration with Uranium) neutron source, a neutron spectrometer (redBubble Technology Industries (BTI) N-Probe), and superheated droplet detectors were used for these measurements. MCNP simulations provided insights into detector responses to fissile materials with varying isotopic compositions, confirming that the system functioned as designed.

Active neutron interrogation

Performance and Achievable Rates of the Gottesman-Kitaev-Preskill Code for Pure-Loss and Amplification Channels

Quantum error-correction codes protect information from realistic noisy channels and lie at the heart of quantum computation and communication tasks. Understanding the optimal performance and other information-theoretic properties, such as the achievable rates, of a given code is crucial, as these factors determine the fundamental limits imposed by the encoding in conjunction with the noise channel. Here, we use the transpose channel to analytically obtain the near-optimal performance of any Gottesman-Kitaev-Preskill (GKP) code under pure loss and pure amplification. We present rigorous connections between GKP code’s near-optimal performance and its dual lattice geometry and average input energy. With no energy constraint, we show that when |𝜏/(1−𝜏)| is an integer, specific families of GKP codes simultaneously achieve the loss and amplification capacity. 𝜏 is the transmissivity (gain) for loss (amplification). Our results establish GKP code as the first structured bosonic code family that achieves the capacity of loss and amplification.

Zheng, Guo [Univ. of Chicago, IL (United States)]

Application of Cyber-Informed Engineering for Protecting BESS

This white paper synthesizes an array of crucial grid services provided by BESS technology, assesses its architecture and communications, and presents a case study for analysis against the principles introduced by Cyber-Informed Engineering (CIE). Furthermore, in walking through the analysis, this paper presents a framework to evaluate risks and solutions when considering BESS components. Asset owners and buyers could perform this analysis to assess their BESS product implementations, alternative inverter-based resources (IBR), and energy management systems (EMS). Battery systems fulfill various roles contingent on the unique market demands and the specific challenges presented by regional grid infrastructures. These roles also vary due to the differing utility models for ownership and operation, which are adapted to meet regional and local capabilities and requirements. Concerns have been raised regarding the potential for adversaries to exploit knowledge of battery operational patterns to orchestrate decisive attacks. However, the security of operational data for these systems may not be the primary vulnerability, as much of this information is already well-understood within the community. Applying a modest degree of subject matter expertise can often yield valuable predictions regarding how a battery will respond under certain conditions, such as grid emergencies, high or low-temperature days, Public Safety Power Shutoff (PSPS) events, and outages. The operational characteristics of batteries are well-documented, and their capabilities, including the risks associated with misoperation and the resulting consequences, are published and understood within the industry. CIE practices represent the next step in gaining functional assurance and providing an acceptable level of risk, regardless of whether a battery vendor can support a trusted and validated supply chain. While this issue has exacerbated supply chain challenges, it is not an isolated condition. This foreign supply route is the primary source of BESS for the U.S. market. Significant efforts are underway through the Bipartisan Infrastructure Law (BIL) to change that. Still, strategic short-term operational mitigations are needed to ensure the security of our operational technology (OT) systems, which are enhanced by instilling trust and are separate from vendors implementing CIE principles.

25 ENERGY STORAGE

COnfirmation using Gamma-ray Non-Imaging Zero-knowledge ANti-mask Time-encoding (COGNIZANT) Final Summary Report

In potential future arms reduction treaties in which the numbers of nuclear warheads may approach small numbers, using delivery systems as a proxy for the warheads themselves may be insufficient. Therefore, a technical means of verifying the presence of a nuclear warhead may become necessary. Verifying that a declared item actually is a warhead is technically challenging within a verification regime: providing assurance to the monitoring party that a presented item is a warhead while protecting sensitive information about that warhead may be required. It is generally believed that strong assurance will require the confirmation of key attributes that may reveal closely-guarded critical design information. This provides high confidence to the monitoring party, but presents a risk of information loss to the host. A verification system must overcome this hurdle. Over the last several decades, systems have been developed that balance host and monitoring partner needs by using sensitive information to confirm treaty accountable items (TAI) as warheads while sequestering that information behind an information barrier (1). These are designed to meet the needs of the host but places the onus on the monitor to authenticate the hardware, firmware, and software. Authentication requires that the monitor confirm that all components of the system have not been modified and work as intended. In 2014, Glaser et al. proposed applying the concept of “zero knowledge protocols” (ZKP) from the field of cryptography to the problem of warhead verification (2). In mathematical cryptography, ZKP is accomplished by challenging one party to solve a problem that is only possible if that party possesses the information being authenticated. After repeated challenges, the party provides confidence that it possesses this information without revealing any details about the information itself. Systems have been in development based on this idea at both Princeton and MIT (2) (3) (4). The final measurement results produced by these systems can be viewed by both the host and the monitoring party without the worry of revealing sensitive information. However, in both of these physical implementations, there remains an information barrier within the system. The need for a digital information barrier to protect a measurement result is eliminated, but it has been replaced with the need to sequester physical components of the system, potentially obfuscating the measurement process itself. Both implementations physically insert information into the system that requires protection to prevent undesired disclosure of sensitive information: in the Princeton method, one must physically load the complement of the expected image of a true warhead into the system, and in the MIT technique, one loads a collection of spectator foils whose thicknesses physically encrypt a measured spectrum. This complicates authentication of the hardware and measurement process. The CONFIDANTE/COGNIZANT concept developed in this project do not load sensitive information into the system at any time, and could therefore open the possibility of allowing the inspector to not only view the final data but also the measurement as it is being performed and all associated equipment.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P

Theft of information in the take-grant protection model

Using the information transfer extensions to the Take-Grant Protection Model, the concept of theft of information is defined and necessary and sufficient conditions for such theft to occur are presented, as well as bounds on the number of actors involved in such theft. Finally, the application of these results to reference monitors are explored.

Bishop, Matt

Theft of information in the take-grant protection model

Questions of information flow are in many ways more important than questions of access control, because the goal of many security policies is to thwart the unauthorized release of information, not merely the illicit obtaining of access rights to that information. The Take-Grant Protection Model is a theoretical tool for examining such issues because conditions necessary and sufficient for information to flow between two objects, and for rights to objects to be obtained or stolen, are known. These results are extended by examining the question of information flow from an object the owner of which is unwilling to release that information. Necessary and sufficient conditions for such theft of information to occur are derived, and bounds on the number of subjects that must take action for the theft to occur are presented. To emphasize the usefulness of these results, the security policies of complete isolation, transfer of rights with the cooperation of an owner, and transfer of information (but not rights) with the cooperation of the owner are presented; the last is used to model a simple reference monitor guarding a resource.

Bishop, Matt

ISS External Microorganisms: A Planetary Protection Experiment to Inform Requirements for Crewed Missions to Mars

We have developed, tested, and flown a caddy capable of collecting aseptic samples from external surfaces of the ISS (International Space Station). The sampling caddy is certified for use during US EVA (extra vehicular activity) and was launched to ISS in the summer of 2023. We are scheduled to collect samples from 6 locations outside ISS during an EVA in May of 2024. We will freeze these samples at -80°C on orbit and return them to Earth. We will then extract and sequence any DNA collected during the EVA using next generation sequencing technologies to characterize the community composition and function of each sample. Measuring the type and quantity of microbes present on the exterior of ISS will allow us to address knowledge gap 2B, “Acceptable levels of microbial/organic releases from humans and support systems” described in a 2019 COSPAR report. Collecting data about microbial release from current crewed vehicles will inform requirements for acceptable leak rates for future crewed missions to Mars. The sampling kit consists of eight commercially available, sterile, DNA free, macrofoam swabs ( 23 mm. diameter ) installed in custom aluminum end effectors. Each end effector is housed in and individual aluminum canister. Each canister contains a 0.2 μm Teflon filter to allow the interior volume to accommodate pressure changes without permitting microbial contaminants to enter the sterile interior volume. A handle repurposed from the space shuttle tile repair kit is used to remove the end effector from the sample canister, collect a sample by swabbing a surface and then replace the end effector in its canister. The canisters and end effectors were cleaned and assembled on Earth. Prior to installing the sterile swab the canisters and end effectors were sterilized in an autoclave at 134°C, 215 kPA, for 7 min.. The final assembly occurred in a sterilized class II biosafety cabinet. We will collect six samples from the 1) airlock vestibule, 2) airlock thermal cover, 3) a gap in the micrometeorite shielding near the airlock, 4) a handrail near the airlock, 5) the CDRA (Carbon Dioxide Removal Assembly) vent, and 6) the VES (Vacuum Exhaust System) vent. The remaining two swabs will be reserved as controls. One swab will be exposed during the EVA without touching any surfaces to act as a blank. The final swab will remain sealed until the entire sampling kit is returned to earth. Based on previously published results from the Russian segment, we hypothesize that there will be detectable microbes at some or all of these locations. Ground-based testing of this sampling caddy confirms that the swabs remain sterile as the canisters transition in and out of vacuum. We were able to retrieve, viable bacterial and fungal cells as well as DNA from samples collected from US space suits during vacuum chamber tests lasting as long as seven hours. Based on these results and feedback from the test subjects the sampling caddy was modified to improve ergonomics and meet US EVA safety requirements. Bayonet probes were added to the sides of the sample kit as alternate mounting points. Additional locking features were added to the end effector and the filter stack to prevent inadvertent release during use. The opening mechanism was changed from one where the end effector was rocked laterally to defeat a ball detent to a twist-to-open threaded closure for similar reasons. Demonstrating, this sampling caddy’s effectiveness during a US EVA will allow us to address knowledge gaps identified in COSPAR reports and begin to define planetary protection requirements for life support systems on crewed missions to mars. This kit could also be used to collect contamination control samples during Artemis missions to verify requirements and could be easily modified for robotic sample collection.

Planetary Protection

Enabling end-to-end secure federated learning in biomedical research on heterogeneous computing environments with APPFLx

Facilitating large-scale, cross-institutional collaboration in biomedical machine learning (ML) projects requires a trustworthy and resilient federated learning (FL) environment to ensure that sensitive information such as protected health information is kept confidential. Specifically designed for this purpose, this work introduces APPFLx - a low-code, easy-to-use FL framework that enables easy setup, configuration, and running of FL experiments. APPFLx removes administrative boundaries of research organizations and healthcare systems while providing secure end-to-end communication, privacy-preserving functionality, and identity management. Furthermore, it is completely agnostic to the underlying computational infrastructure of participating clients, allowing an instantaneous deployment of this framework into existing computing infrastructures. Experimentally, the utility of APPFLx is demonstrated in two case studies: (1) predicting participant age from electrocardiogram (ECG) waveforms, and (2) detecting COVID-19 disease from chest radiographs. Here, ML models were securely trained across heterogeneous computing resources, including a combination of on-premise high-performance computing and cloud computing facilities. By securely unlocking data from multiple sources for training without directly sharing it, these FL models enhance generalizability and performance compared to centralized training models while ensuring data remains protected. In conclusion, APPFLx demonstrated itself as an easy-to-use framework for accelerating biomedical studies across organizations and healthcare systems on large datasets while maintaining the protection of private medical data.

Biomedical Research

Quantum Key Distribution Applicability to Smart Grid Cybersecurity Systems

To meet the increasing demand for electricity and to have a more reliable and resilient electric grid against conventional and extreme events, grid modernization is more crucial now than ever before. This will require the development and deployment of devices that provide advanced communication capabilities. The overall efficiency, reliability, and resilience of the smart grid will be inextricably linked to the exchange of information between these devices. Unfortunately, the increased information flow will increase the potential attack surface and introduce new vulnerabilities. While a smarter grid will depend critically on information flow, these benefits will be accrued only if that information can be protected. Nowadays, information is secured in smart grids primarily through cryptography. However, with the increasing number of sophisticated attacks as well as the increasing computational power, the security of the “classical” cryptographic algorithms is threatened. Quantum information science offers solutions to this problem, specifically quantum key distribution (QKD), which provides a means for the generation and secure distribution of symmetric cryptographic keys. The security of QKD stems ultimately from the very nature of quantum physics. In this paper, we investigate the applicability of QKD to the various smart grid sectors and specific use cases. We have identified 18 smart grid use cases of interest for QKD suitability together with 7 QKD factors used for the assessment of the various use cases. For each use case, the impact to security of the loss of confidentiality, integrity, and/or availability is specified. In addition, the suitability of QKD is assessed for each use case with respect to multiple factors.

24 POWER TRANSMISSION AND DISTRIBUTION