Engineering PapersSearch

SEARCH · Engineering Papers

Results for “information protection”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Autonomous Information Unit for Fine-Grain Data Access Control and Information Protection in a Net-Centric System

As communication and networking technologies advance, networks will become highly complex and heterogeneous, interconnecting different network domains. There is a need to provide user authentication and data protection in order to further facilitate critical mission operations, especially in the tactical and mission-critical net-centric networking environment. The Autonomous Information Unit (AIU) technology was designed to provide the fine-grain data access and user control in a net-centric system-testing environment to meet these objectives. The AIU is a fundamental capability designed to enable fine-grain data access and user control in the cross-domain networking environments, where an AIU is composed of the mission data, metadata, and policy. An AIU provides a mechanism to establish trust among deployed AIUs based on recombining shared secrets, authentication and verify users with a username, X.509 certificate, enclave information, and classification level. AIU achieves data protection through (1) splitting data into multiple information pieces using the Shamir's secret sharing algorithm, (2) encrypting each individual information piece using military-grade AES-256 encryption, and (3) randomizing the position of the encrypted data based on the unbiased and memory efficient in-place Fisher-Yates shuffle method. Therefore, it becomes virtually impossible for attackers to compromise data since attackers need to obtain all distributed information as well as the encryption key and the random seeds to properly arrange the data. In addition, since policy can be associated with data in the AIU, different user access and data control strategies can be included. The AIU technology can greatly enhance information assurance and security management in the bandwidth-limited and ad hoc net-centric environments. In addition, AIU technology can be applicable to general complex network domains and applications where distributed user authentication and data protection are necessary. AIU achieves fine-grain data access and user control, reducing the security risk significantly, simplifying the complexity of various security operations, and providing the high information assurance across different network domains.

Chow, Edward T.

Space Shuttle security policies and programs

The Space Shuttle vehicle consists of the orbiter, external tank, and two solid rocket boosters. In dealing with security two major protective categories are considered, taking into account resource protection and information protection. A review is provided of four basic programs which have to be satisfied. Aspects of science and technology transfer are discussed. The restrictions for the transfer of science and technology information are covered under various NASA Management Instructions (NMI's). There were two major events which influenced the protection of sensitive and private information on the Space Shuttle program. The first event was a manned space flight accident, while the second was the enactment of a congressional bill to establish the rights of privacy. Attention is also given to national resource protection and national defense classified operations.

Keith, E. L.

Autonomous Information Unit: Why Making Data Smart Can also Make Data Secured?

In this paper, we introduce a new fine-grain distributed information protection mechanism which can self-protect, self-discover, self-organize, and self-manage. In our approach, we decompose data into smaller pieces and provide individualized protection. We also provide a policy control mechanism to allow 'smart' access control and context based re-assembly of the decomposed data. By combining smart policy with individually protected data, we are able to provide better protection of sensitive information and achieve more flexible access during emergency conditions. As a result, this new fine-grain protection mechanism can enable us to achieve better solutions for problems such as distributed information protection and identity theft.

data security

IT Challenges for Space Medicine or How do We Protect Medical Information and Still Get Useful Work Done?

Space Medicine provides healthcare services of various types for astronauts throughout their lifetime starting from the time they are selected as astronauts. IT challenges include: protection of private medical information, access from locations both inside and outside NASA, nearly 24x7 access, access during disasters, international partner access, data archiving, off-region backup, secure communication of medical data to people outside the NASA system (e.g. expert consultants), efficient movement of medical record information between locations, search and retrieval of relevant information, and providing all of these services/capabilities within a limited budget. In Space Medicine, we have provided for these in various ways: limit the amount of private medical information stored locally, utilize encryption mechanisms that the international partners can also use, utilize 2-factor authentication, virtualize servers, employ concept-based search, and use of standardized terminologies (SNOMED) and messaging (HL7).

Johnson-Throop, Kathy A.

Informing Planetary Protection Policies for the Future Exploration of Ceres: State of Understanding after the Dawn Mission

We review the current state of understanding of Ceres as it relates to planetary protection policy for future landed missions, including for sample return, to the dwarf planet. The Dawn mission found Ceres to be an intriguing target for a mission, with evidence for the presence of regional, possibly extensive liquid at depth, and local expressions of recent and potentially ongoing activity. The Dawn mission also found a high abundance of carbon in the regolith, interpreted as a mix of carbonates and amorphous carbon, as well as locally high concentrations of organic matter. Key findings from this review are as follows: (1) outside of the region of Occator crater, Ceres shows no geological evidence for conduits from the surface to the interior; and (2) considering the biological potential of Ceres’ deep interior, a surface sample return mission should be considered Category V restricted, unless it can be demonstrated that evaporites sourced from Ceres’ deep brine region, and recently exposed in Occator crater, have not been scattered to the rest of Ceres’ surface; in that case, the probability of returning an unsterilized particle to an acceptably low value is to be determined by a future study. Key Words: Ceres—Planetary protection—Brines—Future missions.

Julie Castillo-Rogez

Considerations for an earth physics information-management service.

In a preliminary investigation into the feasibility of establishing a data center for earth physics, 12 disciplines were considered for inclusion. Estimation of the size of the data base for each indicated a need for storage of approximately 10 to the 10th power characters. The computer-based system deemed most worthy of further investigation was the interactive concept with remote-terminal access. Users are divided into three classes according to how they would access information: with no terminal, with an interactive terminal, and with a multidevice terminal. All these users can be served by the same center without any particular difficulty, but the real benefactor is the user with an interactive terminal, because he can compile, debug, and run programs in one continuous session. Final points stressed are multiprogramming for dynamic resource sharing, hardware modularity for future expansion, and information protection for such a large community of users. It is concluded that a survey should be conducted to gather more information from the potential users of such a system, and that a pilot project should be developed at some location where both earth-physics research and data-processing capabilities already exist.

Martin, R. W.

NASA Tech Briefs, April 2012

Topics include: Computational Ghost Imaging for Remote Sensing; Digital Architecture for a Trace Gas Sensor Platform; Dispersed Fringe Sensing Analysis - DFSA; Indium Tin Oxide Resistor-Based Nitric Oxide Microsensors; Gas Composition Sensing Using Carbon Nanotube Arrays; Sensor for Boundary Shear Stress in Fluid Flow; Model-Based Method for Sensor Validation; Qualification of Engineering Camera for Long-Duration Deep Space Missions; Remotely Powered Reconfigurable Receiver for Extreme Environment Sensing Platforms; Bump Bonding Using Metal-Coated Carbon Nanotubes; In Situ Mosaic Brightness Correction; Simplex GPS and InSAR Inversion Software; Virtual Machine Language 2.1; Multi-Scale Three-Dimensional Variational Data Assimilation System for Coastal Ocean Prediction; Pandora Operation and Analysis Software; Fabrication of a Cryogenic Bias Filter for Ultrasensitive Focal Plane; Processing of Nanosensors Using a Sacrificial Template Approach; High-Temperature Shape Memory Polymers; Modular Flooring System; Non-Toxic, Low-Freezing, Drop-In Replacement Heat Transfer Fluids; Materials That Enhance Efficiency and Radiation Resistance of Solar Cells; Low-Cost, Rugged High-Vacuum System; Static Gas-Charging Plug; Floating Oil-Spill Containment Device; Stemless Ball Valve; Improving Balance Function Using Low Levels of Electrical Stimulation of the Balance Organs; Oxygen-Methane Thruster; Lunar Navigation Determination System - LaNDS; Launch Method for Kites in Low-Wind or No-Wind Conditions; Supercritical CO2 Cleaning System for Planetary Protection and Contamination Control Applications; Design and Performance of a Wideband Radio Telescope; Finite Element Models for Electron Beam Freeform Fabrication Process Autonomous Information Unit for Fine-Grain Data Access Control and Information Protection in a Net-Centric System; Vehicle Detection for RCTA/ANS (Autonomous Navigation System); Image Mapping and Visual Attention on the Sensory Ego-Sphere; HyDE Framework for Stochastic and Hybrid Model-Based Diagnosis; and IMAGESEER - IMAGEs for Education and Research.

Source record

Scalable Asset Discovery, Vulnerability Scanning, and Penetration Testing for Remote Sites and Wireless Spectrums Utilizing an Embedded Linux Plug - PwniPlug and the Raspberry Pi B+ as a Sample Pen Test

All devices attached to the NASA KSC network are subject to security vulnerability scanning and/or penetration testing. In today's changing environment, vulnerable and/or unprotected systems can easily be overlooked. Systems that are not properly managed can become a potential threat to the operational integrity of our systems and networks. This includes all NASA (internal and external) information systems within NASA KSC Internet Protocol (IP) address space, and NASA KSC facilities. The Office of the Chief Information Officer (OCIO) recommends that all NASA Centers and information systems be subject to penetration testing on a regular interval in accordance with the guidelines identified by the National Institute of Standards and Technology (NIST). (ITS-HBK-2810.04-02A) Protecting information and equipment at NASA is an area of increasing concern. In addition to the CPU's on the network; Supervisory, Control and Data Acquisition (SCADA) systems are especially vulnerable because these systems have lacked standards, use embedded controllers with little computational power and informal software, are connected to physical processes, have few operators, and are increasingly also being connected to corporate networks. The scope of work is comprised of several individual components which together build upon previous work by Drew Branch, NASA KSC Intern. The Pwn Plug is the selected COTS (Commercial-Off-The-Shelf) device chosen to test simplification of mandatory IT Security tasks. The device will be utilized to provide services to NASA KSC and enable an assessment of infrastructure soundness and regulatory compliance in an efficient, economical, and business responsive manner. The Pwn Plug is designed as a pen testing appliance which provides a hardware platform that can support commercial penetration testing efforts at significantly reduced costs. The expected outcomes are: 1) External Penetration Testing, 2) Social Engineering, 3) Procedural Documentation, 4) Recommended Remediation Action Plan, 5) System Retest & Remediation Attestation and 6) Final Reports, out briefing and Presentation. Due to physical and material constraints beyond intern and mentor control, the project was redefined as a working pen-test scenario. Limitations of lab availability and tools dictated an academic exercise. This report was developed within the scenario guidelines suggested by the project mentor. The guidelines were to be creative in developing a Pen Test program for a client.

Penetration Testing

Theft of information in the take-grant protection model

Using the information transfer extensions to the Take-Grant Protection Model, the concept of theft of information is defined and necessary and sufficient conditions for such theft to occur are presented, as well as bounds on the number of actors involved in such theft. Finally, the application of these results to reference monitors are explored.

Bishop, Matt

Theft of information in the take-grant protection model

Questions of information flow are in many ways more important than questions of access control, because the goal of many security policies is to thwart the unauthorized release of information, not merely the illicit obtaining of access rights to that information. The Take-Grant Protection Model is a theoretical tool for examining such issues because conditions necessary and sufficient for information to flow between two objects, and for rights to objects to be obtained or stolen, are known. These results are extended by examining the question of information flow from an object the owner of which is unwilling to release that information. Necessary and sufficient conditions for such theft of information to occur are derived, and bounds on the number of subjects that must take action for the theft to occur are presented. To emphasize the usefulness of these results, the security policies of complete isolation, transfer of rights with the cooperation of an owner, and transfer of information (but not rights) with the cooperation of the owner are presented; the last is used to model a simple reference monitor guarding a resource.

Bishop, Matt

ISS External Microorganisms: A Planetary Protection Experiment to Inform Requirements for Crewed Missions to Mars

We have developed, tested, and flown a caddy capable of collecting aseptic samples from external surfaces of the ISS (International Space Station). The sampling caddy is certified for use during US EVA (extra vehicular activity) and was launched to ISS in the summer of 2023. We are scheduled to collect samples from 6 locations outside ISS during an EVA in May of 2024. We will freeze these samples at -80°C on orbit and return them to Earth. We will then extract and sequence any DNA collected during the EVA using next generation sequencing technologies to characterize the community composition and function of each sample. Measuring the type and quantity of microbes present on the exterior of ISS will allow us to address knowledge gap 2B, “Acceptable levels of microbial/organic releases from humans and support systems” described in a 2019 COSPAR report. Collecting data about microbial release from current crewed vehicles will inform requirements for acceptable leak rates for future crewed missions to Mars. The sampling kit consists of eight commercially available, sterile, DNA free, macrofoam swabs ( 23 mm. diameter ) installed in custom aluminum end effectors. Each end effector is housed in and individual aluminum canister. Each canister contains a 0.2 μm Teflon filter to allow the interior volume to accommodate pressure changes without permitting microbial contaminants to enter the sterile interior volume. A handle repurposed from the space shuttle tile repair kit is used to remove the end effector from the sample canister, collect a sample by swabbing a surface and then replace the end effector in its canister. The canisters and end effectors were cleaned and assembled on Earth. Prior to installing the sterile swab the canisters and end effectors were sterilized in an autoclave at 134°C, 215 kPA, for 7 min.. The final assembly occurred in a sterilized class II biosafety cabinet. We will collect six samples from the 1) airlock vestibule, 2) airlock thermal cover, 3) a gap in the micrometeorite shielding near the airlock, 4) a handrail near the airlock, 5) the CDRA (Carbon Dioxide Removal Assembly) vent, and 6) the VES (Vacuum Exhaust System) vent. The remaining two swabs will be reserved as controls. One swab will be exposed during the EVA without touching any surfaces to act as a blank. The final swab will remain sealed until the entire sampling kit is returned to earth. Based on previously published results from the Russian segment, we hypothesize that there will be detectable microbes at some or all of these locations. Ground-based testing of this sampling caddy confirms that the swabs remain sterile as the canisters transition in and out of vacuum. We were able to retrieve, viable bacterial and fungal cells as well as DNA from samples collected from US space suits during vacuum chamber tests lasting as long as seven hours. Based on these results and feedback from the test subjects the sampling caddy was modified to improve ergonomics and meet US EVA safety requirements. Bayonet probes were added to the sides of the sample kit as alternate mounting points. Additional locking features were added to the end effector and the filter stack to prevent inadvertent release during use. The opening mechanism was changed from one where the end effector was rocked laterally to defeat a ball detent to a twist-to-open threaded closure for similar reasons. Demonstrating, this sampling caddy’s effectiveness during a US EVA will allow us to address knowledge gaps identified in COSPAR reports and begin to define planetary protection requirements for life support systems on crewed missions to mars. This kit could also be used to collect contamination control samples during Artemis missions to verify requirements and could be easily modified for robotic sample collection.

Planetary Protection

Evaluating Rock Pool Hydroperiod Fluctuation using Climate Variables to Inform Habitat Monitoring and Protection in the Western Sonoran Desert

As warming and drying trends continue to impact the greater American Southwest, effective ecosystem management increasingly relies upon understanding the relationships between climate and water resources. Ephemeral freshwater rock pools, known as tinajas, have great ecological and cultural importance as some of the only sources of surface water in the western Sonoran Desert (WSD). Tinaja flooding and drying cycles, known as hydroperiods, vary based on meteorologic and climatologic conditions; however, a lack of extensive research relating climatic impacts to tinajas puts these critical ecosystems further at risk. Tinajas throughout the WSD are monitored by the National Park Service (NPS) using resource intensive strategies including in situ trail camera observation and direct measurement. To aid NPS monitoring efforts, this research used remotely sensed climate data to analyze spatiotemporal climate trends and relationships between climate variables and tinaja hydroperiods in the WSD between 1979–2022. Using Aqua and Terra Moderate Resolution Imaging Spectroradiometers (MODIS), University of Idaho Gridded Surface Meteorological Dataset (gridMET), and OpenET data, the project analyzed land surface temperature, evapotranspiration, precipitation, wind velocity, and solar radiation. The team generated climate anomaly time series and climate normal maps for the WSD, identifying statistically significant spatial and temporal trends. These data were then compared to daily, qualitative in situ hydroperiod observations taken between 2019–2022. This work will be used by the NPS to inform the monitoring and protection of tinajas in the WSD. Findings contribute to a limited body of research concerning climate and tinajas, which are often overlooked despite their disproportionate ecological importance.

Annie Britton

Western Sonoran Desert Water Resources: Evaluating Rock Pool Hydroperiod Fluctuation using Climate Variables to Inform Habitat Monitoring and Protection in the Western Sonoran Desert

Ephemeral freshwater rock pools, known as tinajas, have great biologic and cultural importance as sources of surface water in the western Sonoran Desert (WSD). Tinaja flooding and drying cycles, known as hydroperiods, vary based on meteorologic and climatologic conditions; however, a lack of extensive research relating climatic impacts to tinajas puts these critical ecosystems further at risk. The National Park Service (NPS) and the University of Arizona monitor the physical and ecological condition of tinajas in Organ Pipe Cactus National Monument (OPCNM), AZ, using resource-intensive strategies: in situ trail cameras and direct measurements. To aid monitoring efforts, the NASA DEVELOP team aimed to incorporate remote sensing into NPS strategies by analyzing spatiotemporal climate data and tinaja hydroperiods in OPCNM between 1979–2022. Using Aqua and Terra Moderate Resolution Imaging Spectroradiometers (MODIS), University of Idaho Gridded Surface Meteorological Dataset (gridMET), and OpenET data, the team generated climatology maps and time series for OPCNM. The team compared these data to daily in situ hydroperiod observations from the University of Arizona between 2019–2022. Climate maps and time series showed increases in temperature and solar radiation (p<0.05), while analyses of in situ data showed correlations of hydroperiods with precipitation and evapotranspiration. End products identified high-risk tinajas and demonstrated that Earth observations can successfully be correlated with in situ hydroperiod observations. These results will support NPS efforts to prioritize water resource management and inform protocols driving the conservation of tinajas in OPCNM.

Anne Britton

The sharing of rights and information in a capability-based protection system

The question of sharing of rights and information in the Take-Grant Protection Model is examined by concentrating on the similarities between the two; in order to do this, new theorems are stated and proven for each that specifically show the similarities. The proof for one of the original theorems is also provided. These statements of necessary and sufficient conditions are contrasted to illustrate the proposition that transferring rights and transferring information are fundamentally the same, as one would expect in a capability-based system. Directions are then discussed for future research in light of these results.

Bishop, Matt

NASA Fire Protection

This viewgraph presentation provides information on fire protection operations and administration at Stennis Space Center (SSC). The presentation also lists innovative practices and recent improvements.

Clark, Theodore

Tailoring NIST Security Controls for the Ground System: Selection and Implementation -- Recommendations for Information System Owners

The National Aeronautics and Space Administration (NASA) invests millions of dollars in spacecraft and ground system development, and in mission operations in the pursuit of scientific knowledge of the universe. In recent years, NASA sent a probe to Mars to study the Red Planet's upper atmosphere, obtained high resolution images of Pluto, and it is currently preparing to find new exoplanets, rendezvous with an asteroid, and bring a sample of the asteroid back to Earth for analysis. The success of these missions is enabled by mission assurance. In turn, mission assurance is backed by information assurance. The information systems supporting NASA missions must be reliable as well as secure. NASA - like every other U.S. Federal Government agency - is required to manage the security of its information systems according to federal mandates, the most prominent being the Federal Information Security Management Act (FISMA) of 2002 and the legislative updates that followed it. Like the management of enterprise information technology (IT), federal information security management takes a "one-size fits all" approach for protecting IT systems. While this approach works for most organizations, it does not effectively translate into security of highly specialized systems such as those supporting NASA missions. These systems include command and control (C&C) systems, spacecraft and instrument simulators, and other elements comprising the ground segment. They must be carefully configured, monitored and maintained, sometimes for several years past the missions' initially planned life expectancy, to ensure the ground system is protected and remains operational without any compromise of its confidentiality, integrity and availability. Enterprise policies, processes, procedures and products, if not effectively tailored to meet mission requirements, may not offer the needed security for protecting the information system, and they may even become disruptive to mission operations. Certain protective measures for the general enterprise may not be as efficient within the ground segment. This is what the authors have concluded through observations and analysis of patterns identified from the various security assessments performed on NASA missions such as MAVEN, OSIRIS-REx, New Horizons and TESS, to name a few. The security audits confirmed that the framework for managing information system security developed by the National Institute of Standards and Technology (NIST) for the federal government, and adopted by NASA, is indeed effective. However, the selection of the technical, operational and management security controls offered by the NIST model - and how they are implemented - does not always fit the nature and the environment where the ground system operates in even though there is no apparent impact on mission success. The authors observed that unfit controls, that is, controls that are not necessarily applicable or sufficiently effective in protecting the mission systems, are often selected to facilitate compliance with security requirements and organizational expectations even if the selected controls offer minimum or non-existent protection. This paper identifies some of the standard security controls that can in fact protect the ground system, and which of them offer little or no benefit at all. It offers multiple scenarios from real security audits in which the controls are not effective without, of course, disclosing any sensitive information about the missions assessed. In addition to selection and implementation of controls, the paper also discusses potential impact of recent legislation such as the Federal Information Security Modernization Act (FISMA) of 2014 - aimed at the enterprise - on the ground system, and offers other recommendations to Information System Owners (ISOs).

GOVERNANCE