CISA Releases 2023 Year in Review Showcasing Efforts to Protect Critical Infrastructure

News In Brief – Source: US Computer Emergency Readiness Team

WASHINGTON – Today, the Cybersecurity and Infrastructure Security Agency (CISA) released its fourth annual Year in Review showcasing CISA’s work to protect the nation from cyber and physical threats, while working to increase the resilience of critical infrastructure Americans rely on every day. The 2023 Year in Review reflects on the agency’s accomplishments across its broad cybersecurity, infrastructure security and emergency communications missions as the nation and the world adapted to technological advances, spillover from international events and other major events. In 2024, CISA will continue to develop and deliver tools, training, technical expertise and other resources to help our critical infrastructure partners increase their own resilience and defenses against evolving risks. 

“This Year in Review report demonstrates CISA’s exceptional work in 2023 to protect critical infrastructure,” said CISA Director Jen Easterly. “It not only celebrates our progress from the past year but also spotlights groundbreaking milestones and pioneering ‘firsts’ achieved by the agency. These efforts are a testament to and reflect the dedication of CISA’s workforce. Because of their commitment to the mission, the critical infrastructure systems that Americans rely on every day are more secure and resilient than ever.”  

In 2023, the CISA accomplishments included:  

  • Promoting Secure by Design Principles. As part of an Administration-wide push to promote secure software development, CISA launched its Secure by Design campaign in April 2023. This effort strives for a future where technology is safe, secure and resilient by design by encouraging software manufacturers to take ownership of customer security outcomes. In October 2023, CISA and 17 U.S. and international partners published an update to a joint Secure by Design white paper on “Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Secure by Design Software.” Originally released April 13, 2023, this paper urges software manufacturers to revamp their design and development programs to produce only secure by design products. It also emphasizes three core principles: 1.) Take ownership of customer security outcomes, 2.) Embrace radical transparency and accountability, and 3.) Lead from the top. 
  • Leading on Artificial Intelligence. CISA published its first Roadmap for Artificial Intelligence (AI) in November 2023, adding to the significant U.S. Department of Homeland Security and broader whole-of-government effort to ensure the secure development and implementation of AI capabilities. This Roadmap outlines a whole-of-agency plan to assess possible cyber-related risks to the use of AI, provide guidance to the critical infrastructure sectors that Americans rely on every hour of every day, and capitalize on AI’s potential to improve U.S. cyber defenses.   
  • Reducing the Risk of Ransomware. In March 2023, CISA launched the Pre-Ransomware Notification Initiative, which measurably reduces risk by warning organizations of early-stage ransomware activity. Since the Initiative’s launch, the agency conducted more than 1,000 pre-ransomware notifications across a variety of critical infrastructure sectors and to partners abroad.  
  • Encouraging Cyber Hygiene. In September 2023, CISA launched its Secure Our World program. Secure Our World is a new and enduring cybersecurity awareness program that emphasizes four simple cyber hygiene steps everyone should implement and continuously improve upon: 1.) Use Strong Passwords and a Password Manager, 2.) Turn On Multifactor Authentication, 3.) Recognize and Report Phishing, and 4.) Update Software. The campaign featured CISA’s first-ever public service announcement (PSA) and garnered significant public attention though outreach efforts including television, radio and billboard ads, podcasts, media coverage, social media and beyond.  
  • Supporting Critical Infrastructure. CISA enhanced its engagement with “target rich, resource poor” organizations, including the Water and Wastewater Sector, K-12 Education Subsector, Healthcare and Public Health Sector and the Election Security Sector. In 2023, CISA completed more than 6,700 stakeholder engagements with government and private sector participants to share threat information and promote its cybersecurity services. 
  • Enhancing Emergency Communications. In 2023, CISA accumulated new subscribers to CISA’s Priority Telecommunication Services (PTS) program which enables essential personnel to communicate when landline or wireless networks become degraded, congested or otherwise unavailable. The PTS program covers wireline communications under Government Emergency Telecommunications Service (GETS), wireless voice communications under Wireless Priority Service (WPS), and priority repair and installation of critical voice and data circuits under Telecommunications Service Priority (TSP). In 2023, GETS added 51,023 new subscribers, thanks in large part to focused outreach during the second annual Emergency Communications Month in April. In addition, WPS users increased by 283,357 subscribers. TSP also added restoration priority to 18,307 new circuits that support national security emergency preparedness missions. 
  • Providing Resources to State and Local Governments. In 2023, CISA and the Federal Emergency Management Agency (FEMA) jointly implemented the State and Local Cybersecurity Grant Program (SLCGP). The SLCGP is a first-of-its-kind cybersecurity grant program specifically for state, local and territorial governments across the country.  In September 2023, CISA and FEMA announced the of Notice of Funding Opportunity for the Tribal Cybersecurity Grant Program, allocating $18.2 million to bolster cybersecurity among federally-recognized tribes.  
  • Strengthening Regional Election Security Support. In 2023, CISA established dedicated election security advisors (ESAs) in each of its 10 regions to provide support and resources to promote secure elections. These ESAs work directly for CISA’s Regional Directors and with the agency’s cybersecurity and protective security advisors to ensure CISA’s capabilities and services are being optimally employed to meet the unique needs of each state or locality. 
  • Improving Security for Chemical Facilities. CISA celebrated the second anniversary of its ChemLock voluntary program in November 2023. This program provides facilities possessing dangerous chemicals with tailored, scalable, no-cost services and tools to improve their chemical cyber and physical security posture. 

This digitally interactive 2023 Year in Review takes on a new look and feel, providing the reader with a brief snapshot of CISA’s accomplishments while linking back to corresponding CISA.gov webpages for a deeper dive into its programs and initiatives.  

Read the full Year in Review to learn more about CISA’s accomplishments and success stories from 2023. 

###

About CISA 

As the nation’s cyber defense agency and national coordinator for critical infrastructure security, the Cybersecurity and Infrastructure Security Agency leads the national effort to understand, manage, and reduce risk to the digital and physical infrastructure Americans rely on every hour of every day.

Visit CISA.gov for more information and follow us on TwitterFacebookLinkedIn, Instagram.

Release Cybersecurity Guidance on Chinese-Manufactured UAS for Critical Infrastructure Owners and Operators 

News In Brief – Source: US Computer Emergency Readiness Team

WASHINGTON – Today, the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) released, Cybersecurity Guidance: Chinese-Manufactured Unmanned Aircraft Systems (UAS), to raise awareness of the threats posed by Chinese-manufactured UAS and to provide critical infrastructure and state, local, tribal, and territorial (SLTT) partners with recommended cybersecurity safeguards to reduce the risk to networks and sensitive information. 

The People’s Republic of China (PRC) has enacted laws that provide the government with expanded legal grounds for accessing and controlling data held by firms in China. The use of Chinese-manufactured UAS in critical infrastructure operations risks exposing sensitive information to PRC authorities. This guidance outlines the potential vulnerabilities to networks and sensitive information when operated without the proper cybersecurity protocols and the potential consequences that could result.  

“Our nation’s critical infrastructure sectors, such as energy, chemical and communications, are increasingly relying on UAS for various missions that ultimately reduce operating costs and improve staff safety. However, the use of Chinese-manufactured UAS risks exposing sensitive information that jeopardizes U.S. national security, economic security, and public health and safety,” said CISA Executive Assistant Director for Infrastructure Security, Dr. David Mussington. “With our FBI partners, CISA continues to call urgent attention to China’s aggressive cyber operations to steal intellectual property and sensitive data from organizations. We encourage any organization procuring and operating UAS to review the guidance and take action to mitigate risk. We must work together to ensure the security and resilience of our critical infrastructure.”  

“Without mitigations in place, the widespread deployment of Chinese-manufactured UAS in our nation’s key sectors is a national security concern, and it carries the risk of unauthorized access to systems and data,” said Assistant Director of the FBI’s Cyber Division, Bryan A. Vorndran. “The FBI and our CISA partners have issued UAS guidance in order to help safeguard our critical infrastructure and reduce the risk for all of us.”   

Critical infrastructure organizations are encouraged to operate UAS that are secure-by-design and manufactured by U.S. companies. This guidance offers cybersecurity recommendations that organizations should consider as part of their UAS program, policies, and procedures.  

For more information, please visit CISA’s Unmanned Aircraft Systems Resources webpage.  

About CISA 

As the nation’s cyber defense agency and national coordinator for critical infrastructure security, the Cybersecurity and Infrastructure Security Agency leads the national effort to understand, manage, and reduce risk to the digital and physical infrastructure Americans rely on every hour of every day.

Visit CISA.gov for more information and follow us on Twitter, Facebook, LinkedIn, Instagram. 

CISA, FBI and EPA Release Incident Response Guide for Water and Wastewater Systems Sector 

News In Brief – Source: US Computer Emergency Readiness Team

With WWS Sector contributions, guide provides recommended actions and available resources throughout cyber incident response lifecycle 

WASHINGTON – The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and Environmental Protection Agency (EPA) published a guide today to assist owners and operators in the Water and Wastewater Systems (WWS) Sector with best practices for cyber incident response and information about federal roles, resources and responsibilities for each stage of the response lifecycle. Technical expertise is not required to understand and use this guide.   

Developed in collaboration with over 25 WWS Sector industry, nonprofit, and state/local government partners, this resource covers the four stages of the incident response lifecycle:  

  1. Preparation: WWS Sector organizations should have an incident response plan in place, implement available services and resources to raise their cyber baseline, and engage with the WWS Sector cyber community.  
  2. Detection and analysis: Accurate and timely reporting and rapid collective analysis are essential to understand the full scope and impact of a cyber incident. The guidance provides information on validating an incident, reporting levels, and available technical analysis and support.   
  3. Containment, eradication, and recovery: While WWS Sector utilities are conducting their incident response plan, federal partners are focusing on coordinated messaging and information sharing, and remediation and mitigation assistance.  
  4. Post-incident activities. Evidence retention, using collected incident data, and lessons learned are the overarching elements for a proper analysis of both the incident and how responders handled it.  

“The Water and Wastewater Systems sector is under constant threat from malicious cyber actors. This timely and actionable guidance reflects an outstanding partnership between industry, nonprofit, and government partners that came together with EPA, FBI and CISA to support this essential sector. We encourage every WWS entity to review this joint guide and implement its recommended actions,” said CISA Executive Assistant Director for Cybersecurity, Eric Goldstein. “In the new year, CISA will continue to focus on taking every action possible to support ‘target-rich, cyber-poor’ entities like WWS utilities by providing actionable resources and encouraging all organizations to report cyber incidents. Our regional team members across the country will continue to engage with WWS partners to provide access to CISA’s voluntary services, such as enrollment in our Vulnerability Scanning, and serve as a resource for continued improvement.”  

“The Water and Wastewater Systems Sector is a vital part of our critical infrastructure, and the FBI will continue to combat cyber actors who threaten it,” said Assistant Director Bryan Vorndran of the FBI’s Cyber Division. “A key part of our cyber strategy is building strong partnerships and sharing threat information with the owners and operators of critical infrastructure before they are hit with an attack.”   

“Cyber threats to the water sector represent a real and urgent risk to safe drinking water and wastewater services that our nation relies on. The incident response guide assists utilities with approaches for collaboration with federal entities on lowering cyber risk in our nation’s drinking water and wastewater systems,” said EPA Assistant Administrator for Water, Radhika Fox. “EPA is committed to working with our federal, state, and water sector partners to increase the sector’s resilience and improve cyber-resilience practices.” 

All WWS utilities are encouraged to use this incident response guide to augment their incident response planning and collaboration with federal partners and the WWS before, during, and following a cyber incident. Familiarity with this guide will better prepare WWS utilities to respond to—and recover from—a cyber incident.  

For more information and resources, WWS utilities are encouraged to visit CISA’s Water and Wastewater Systems Cybersecurity webpage.  

Partners that contributed to this guide include:  

  • AlexRenew  
  • American Water  
  • Association of State Drinking Water Administrators (ASDWA)  
  • Center on Cyber and Technology Innovation (CCTI)  
  • City of Dover  
  • Cyber Readiness Institute (CRI)  
  • Department of Homeland Security’s Office of Intelligence and Analysis 
  • District of Columbia Water (DC Water)  
  • Dragos 
  • East Bay Municipal Utility District  
  • EMA Inc.  
  • Google/Mandiant 
  • International Society of Automation (ISA)  
  • Maine DHHS CDC Drinking Water Program 
  • Microsoft  
  • New Jersey Cybersecurity & Communications Integration Cell (NJCCIC)  
  • Platte Canyon Water & Sanitation DistrictSan Francisco Public Utilities Commission (SFPUC) 
  • Schneider Electric 
  • Tenable  
  • Tetra Tech  
  • Trinity River Authority of Texas  
  • Water Environment Federation  
  • Water Information Sharing and Analysis Center (WaterISAC)  
  • West Yost Inc.  
  • Xylem 
  • Individuals from American Water Works Association (AWWA) 

About CISA 

As the nation’s cyber defense agency and national coordinator for critical infrastructure security, the Cybersecurity and Infrastructure Security Agency leads the national effort to understand, manage, and reduce risk to the digital and physical infrastructure Americans rely on every hour of every day.

Visit CISA.gov for more information and follow us on Twitter, Facebook, LinkedIn, Instagram.

Gessler GmbH WEB-MASTER

News In Brief – Source: US Computer Emergency Readiness Team

View CSAF

1. EXECUTIVE SUMMARY

  • CVSS v3 9.8
  • ATTENTION: Exploitable Remotely/Low attack complexity
  • Vendor: Gessler GmbH
  • Equipment: WEB-MASTER
  • Vulnerabilities: Use of Weak Credentials, Use of Weak Hash

2. RISK EVALUATION

Successful exploitation of these vulnerabilities could allow a user to take control of the web management of the device. An attacker with access to the device could also extract and break the password hashes for all users stored on the device.

3. TECHNICAL DETAILS

3.1 AFFECTED PRODUCTS

The following versions of Gessler GmbH WEB-MASTER, an emergency lighting management system, are affected:

  • WEB-MASTER: version 7.9

3.2 Vulnerability Overview

3.2.1 USE OF WEAK CREDENTIALS CWE-1391

Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web management of the device.

CVE-2024-1039 has been assigned to this vulnerability. A CVSS v3.1 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

3.2.2 USE OF WEAK HASH CWE-328

Gessler GmbH WEB-MASTER user account is stored using a weak hashing algorithm. The attacker can restore the passwords by breaking the hashes stored on the device.

CVE-2024-1040 has been assigned to this vulnerability. A CVSS v3.1 base score of 4.4 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).

3.3 BACKGROUND

  • CRITICAL INFRASTRUCTURE SECTORS: Multiple
  • COUNTRIES/AREAS DEPLOYED: Worlwide
  • COMPANY HEADQUARTERS LOCATION: Germany

3.4 RESEARCHER

Felix Eberstaller and Nino Fürthauer of Limes Security reported these vulnerabilities to CISA.

4. MITIGATIONS

Gessler GmbH recommends updating EZ2 to 3.2 or greater and WebMaster to 4.4 or greater to mitigate these vulnerabilities. Updates have to be applied by Gessler GmbH technicians. For more information contact Gessler GmbH.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.

Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.

5. UPDATE HISTORY

  • February 1, 2024: Initial Publication

CISA Releases Two Industrial Control Systems Advisories

News In Brief – Source: US Computer Emergency Readiness Team

CISA released two Industrial Control Systems (ICS) advisories on February 1, 2024. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.

CISA encourages users and administrators to review the newly released ICS advisories for technical details and mitigations.

Juniper Networks Releases Security Bulletin for Juniper Secure Analytics

News In Brief – Source: US Computer Emergency Readiness Team

Juniper Networks released a security bulletin to address multiple vulnerabilities affecting Juniper Secure Analytics optional applications. A cyber threat actor could exploit one of these vulnerabilities to take control of an affected system.

CISA encourages users and administrators to review the Juniper Security Bulletin JSA76718 and apply the necessary updates.

NASA Puts Next-Gen Exoplanet-Imaging Technology to the Test

Source: NASA

A cutting-edge tool to view planets outside our solar system has passed two key tests ahead of its launch as part of the agency’s Roman Space Telescope by 2027.
The Coronagraph Instrument on NASA’s Nancy Grace Roman Space Telescope will demonstrate new technologies that could vastly increase the number of planets outside our solar system (exoplanets) that scientists can directly observe. Designed and built at the agency’s Jet Propulsion Laboratory in Southern California, it recently passed a series of critical tests ahead of launch. That includes tests to ensure the instrument’s electrical components don’t interfere with those on the rest of the observatory and vice versa.  
“This is such an important and nerve-wracking stage of building a spacecraft instrument, testing whether or not everything works as intended,” said Feng Zhao, deputy project manager for the Roman Coronagraph at JPL. “But we have an amazing team who built this thing, and it passed the electrical components tests with flying colors.”
A coronagraph blocks light from a bright cosmic object, like a star, so that scientists can observe a nearby object that would otherwise be hidden by the glare. (Think of a car’s sun visor.) The light reflected or emitted by a planet carries information about the chemicals in the planet’s atmosphere and other potential signs of habitability, so coronagraphs will likely be a critical tool in the search for life beyond our solar system.
But if scientists were trying to obtain images of an Earth-like planet in another solar system (same size, same distance from a star similar to our Sun), they wouldn’t be able to see the planet in the star’s glare, even with the best coronagraphs and most powerful telescopes operating today.

The Roman Coronagraph aims to change that paradigm. The innovations that have gone into the instrument should make it possible to see planets similar to Jupiter in size and distance from their star. The Coronagraph team expects these advances will help enable the leap to viewing more Earth-like planets with future observatories.
As a technology demonstration, the Roman Coronagraph’s primary goal is to test technologies that have not been flown in space before. Specifically, it will test sophisticated light-blocking capabilities that are at least 10 times better than what’s currently available. Scientists expect to push its performance even further to observe challenging targets that could yield novel scientific discoveries.
Making the Grade
Even with the Coronagraph blocking a star’s light, a planet will still be exceptionally faint, and it might take a full month of observations to get a good picture of the distant world. To make these observations, the instrument’s camera detects individual photons, or single particles of light, making it far more sensitive than previous coronagraphs.
That’s one reason the recent tests were crucial: The electrical currents that send power to the spacecraft’s components can produce faint electrical signals, mimicking light in the Coronagraph’s sensitive cameras – an effect known as electromagnetic interference. Meanwhile, signals from the Coronagraph could similarly disrupt Roman’s other instruments.
The mission needs to ensure neither will happen when the telescope is operating in an isolated, electromagnetically quiet environment 1 million miles (about 1.5 million kilometers) from Earth. So a team of engineers put the fully assembled instrument in a special isolated, electromagnetically quiet chamber at JPL and turned it on to full power.
They measured the instrument’s electromagnetic output to make sure it fell below the level required to operate aboard Roman. The team used injection clamps, transformers, and antennas to produce electrical disturbances and radio waves similar to what the rest of the telescope will generate. Then they measured the instrument’s performance, looking for excessive noise in the camera images and other unwanted responses from the optical mechanisms.
“The electric fields we generate with the antennas are about the same strength as what’s generated by a computer screen,” said Clement Gaidon, the Roman Coronagraph electrical systems engineer at JPL. “That’s a pretty benign level, all things considered, but we have very sensitive hardware onboard. Overall, the instrument did a fantastic job navigating across the electromagnetic waves. And props to the team for wrapping this test campaign in record time!”
A Wide Field of View
The lessons learned from the Coronagraph technology demonstration will be separate from the Roman Space Telescope’s primary mission, which includes multiple science objectives. The mission’s principal tool, the Wide Field Instrument, is designed to generate some of the largest images of the universe ever taken from space. These images will enable Roman to conduct groundbreaking surveys of cosmic objects such as stars, planets, and galaxies, and study the large-scale distribution of matter in the universe.
For example, by taking repeated images of the center of the Milky Way – like a multiyear time-lapse movie – the Wide Field Instrument will discover tens of thousands of new exoplanets. (This planet survey will be separate from the observations made by the Coronagraph).
Roman will also make 3D maps of the cosmos to explore how galaxies have formed and why the universe’s expansion is speeding up, measuring the effects of what astronomers call “dark matter” and “dark energy.” With these wide-ranging capabilities, Roman will help answer questions about big and small features of our universe.
More About the Mission
The Nancy Grace Roman Space Telescope is managed at NASA’s Goddard Space Flight Center in Greenbelt, Maryland, with participation by JPL and Caltech/IPAC in Southern California, the Space Telescope Science Institute in Baltimore, and a science team comprising scientists from various research institutions. The primary industrial partners are Ball Aerospace & Technologies Corp. in Boulder, Colorado; L3Harris Technologies in Melbourne, Florida; and Teledyne Scientific & Imaging in Thousand Oaks, California.
The Roman Coronagraph Instrument was designed and is being built at JPL, which manages the instrument for NASA. Contributions were made by ESA (the European Space Agency), JAXA (the Japanese Aerospace Exploration Agency), the French space agency CNES (Centre National d’Études Spatiales), and the Max Planck Institute for Astronomy in Germany. Caltech, in Pasadena, California, manages JPL for NASA. The Roman Science Support Center at Caltech/IPAC partners with JPL on data management for the Coronagraph and generating the instrument’s commands.
For more information about the Roman telescope, visit:
https://roman.gsfc.nasa.gov/
News Media Contacts
Calla CofieldJet Propulsion Laboratory, Pasadena, Calif.626-808-2469calla.e.cofield@jpl.nasa.gov
Claire AndreoliNASA’s Goddard Space Flight Center, Greenbelt, Md.301-286-1940claire.andreoli@nasa.gov
2024-010      

NASA Invests in Small Business Tech to Advance Alternative Fuels, More

Source: NASA

Transitioning cutting-edge research from the lab to life-changing technology in the market is no easy feat and the cost of failure is high, especially for small businesses. One of the ways NASA helps is through its Small Business Technology Transfer (STTR) program, which supports small businesses, and their research institution partners during early-stage research and development on a range of technologies that can benefit all.
After proving their concepts during Phase I, and finalizing negotiations, NASA announced Thursday 21 small businesses will receive Phase II awards worth up to $850,000 each. The funds will go toward developing, demonstrating, and delivering innovative technologies over the next 24 months, bringing them one step closer to infusion into a NASA mission or commercialization in the marketplace.
Each small business will collaborate with a research institution such as a university or Federally Funded Research and Development Center on their work—a requirement of STTR and a key differentiator from its sister program, Small Business Innovation Research (SBIR).
“The STTR program exists to unlock the power and innovative thinking enabled by partnership between small businesses and research institutions, said Jenn Gustetic, director of Early Stage Innovation and Partnerships under the Space Technology Mission Directorate (STMD) at the NASA Headquarters in Washington. “NASA is committed to creating equitable opportunities and removing barriers for underrepresented audiences, so we’re proud that in this batch of awards, one-third of the partnering research institutions are Minority Serving Institutions (MSIs).”
One of the awardees is SSS Optical Technologies, LLC, a Huntsville, Alabama, small business partnering with Oakwood University, a Historically Black Colleges and University also based in Huntsville. Together they will use the Phase II award to develop an innovative protective coating that absorbs damaging UV radiation and converts it into energy to power solar cells. The team prepared for their journey by participating in M-STTR—now the MUREP Partnership Learning Award Notification (MPLAN)—an initiative that connects MSIs with NASA to maximize the potential for long term collaborations and enhance future funding opportunities. Building off that early success, they won an STTR Phase I award, during which they demonstrated a 5% gain in efficiency while reducing radiation damage by 400%. The team will now focus their Phase II period on optimizing coating factors (composition, structure, and application method) for better efficiency and operational lifetime. If successful, their technology could find use in NASA’s Advanced Solar Sailing Technologies arena or in solar panels used in the commercial market.
“Our program is in a unique position to support small businesses and their research institution partners to de-risk their technologies with funding and guidance,” said Jason L. Kessler, program executive for NASA’s SBIR/STTR program. “We want these awards to give each team the backing needed to showcase the impact the technologies can have inside and outside NASA’s walls.”
This includes small businesses like Air Company Holdings, whichwas selected for a Phase II award to develop an alternative to fossil fuels. Based in Brooklyn, New York, the company is partnering with New York University to create a carbon dioxide hydrogenation technology that NASA can use to produce sustainable rocket fuel. The team will use their Phase II period to expand on the process model created in Phase I and optimize their fuel production and downstream processing, ensuring the produced fuel meets international standards. In addition to use as rocket fuel, this sustainable fuel could be used on Earth to address greenhouse gas emissions in the aviation industry or on Mars to produce a stable and storable fuel in-situ—using only the Martian atmosphere, water, and solar photovoltaic electricity—which could be used to power habitats, and more.
The NASA SBIR/STTR program is part of NASA’s Space Technology Mission Directorate and is managed by NASA’s Ames Research Center in California’s Silicon Valley. To learn more about the NASA SBIR/STTR program, visit:
https://sbir.nasa.gov

Funding Future Tech: NASA Names 2024 Innovative Concept Studies

Source: NASA

NASA selected the 2024 Phase I awardees for its program to fund ideas that could  innovate for the benefit of all and transform future agency missions. From proposals to explore low Earth orbit to the stars, the 13 concepts chosen stem from companies and institutions across the United States.
The NIAC (NASA Innovative Advanced Concepts) program fosters pioneering ideas by funding early-stage technology concept studies for future consideration and potential commercialization. The combined award is a maximum of $175,000 in grants to evaluate technologies that could enable tomorrow’s space missions.
“The daring missions NASA undertakes for the benefit of humanity all begin as just an idea, and NIAC is responsible for inspiring many of those ideas,” said NASA Associate Administrator Jim Free. “The Ingenuity helicopter flying on Mars and instruments on the MarCO deep space CubeSats can trace their lineage back to NIAC, proving there is a path from creative idea to mission success. And, while not all these concepts will fly, NASA and our partners worldwide can learn from fresh approaches and may eventually use technologies advanced by NIAC.”
This year’s class will explore sample return from the surface of Venus, fixed-wing flight on Mars, a swarm of probes traveling across interstellar space, and more. All NIAC studies are in the early stages of conceptual development and are not considered official NASA missions. 
Ge-Cheng Zha, Coflow Jet LLC in Florida, proposed flying the first fixed-wing, electric vertical takeoff, and landing craft on Mars. The vehicle nicknamed “MAGGIE,” could extend humanity’s ability to explore and conduct science on the Red Planet. 
Thomas Eubanks, Space Initiatives Inc. in Florida, believes a swarm of tiny spacecraft could travel to Proxima Centauri this century, sending back data about the Sun’s nearest interstellar neighbor using a novel laser sailcraft and laser communications.
Geoff Landis, NASA’s Glenn Research Center in Cleveland, proposed a spacecraft that can not only survive Venus’ harsh environment but return a sample from the surface using innovations in high-temperature technology and solar aircraft. 
“The diversity of this year’s Phase I projects – from quantum sensors observing Earth’s atmosphere to a coordinated swarm of spacecraft communicating from the next star – is a testament to the truly innovative community reached by NIAC,” said Mike LaPointe, NIAC program executive at NASA Headquarters in Washington. “The NIAC awards highlight NASA’s commitment to continue pushing the boundaries of what’s possible.”
Using their NIAC grants, the researchers, known as fellows, will investigate the fundamental premise of their concepts, roadmap necessary technology development, identify potential challenges, and look for opportunities to bring these concepts to life.
In addition to the projects mentioned above, the other selectees to receive 2024 NIAC Phase I grants are:
Steven Benner, Foundation for Applied Molecular Evolution, Florida: Add-on to Large-scale Water Mining Operations on Mars to Screen for Introduced and Alien Life
James Bickford, Charles Stark Draper Laboratory, Massachusetts: Thin Film Isotope Nuclear Engine Rocket
Peter Cabauy, City Labs, Inc., Florida: Autonomous Tritium Micropowered Sensors
Kenneth Carpenter, NASA’s Goddard Space Flight Center, Greenbelt, Maryland: A Lunar Long-Baseline Optical Imaging Interferometer: Artemis-enabled Stellar Image
Matthew McQuinn, University of Washington, Seattle: Solar System-Scale VLBI to Dramatically Improve Cosmological Distance Measurements
Aaswath Pattabhi Raman, University of California, Los Angeles: Electro-Luminescently Cooled Zero-Boil-Off Propellant Depots Enabling Crewed Exploration of Mars 
Alvaro Romeo-Calvo, Georgia Tech Research Corporation, Atlanta: Magnetohydrodynamic Drive for Hydrogen and Oxygen Production in Mars Transfer
Lynn Rothschild, NASA’s Ames Research Center, California’s Silicon Valley: Detoxifying Mars: The Biocatalytic Elimination of Omnipresent Perchlorates
Ryan Sprenger, Fauna Bio Inc., California: A revolutionary approach to interplanetary space travel: Studying Torpor in Animals for Space-health in Humans
Beijia Zhang, MIT’s Lincoln Lab, Massachusetts: LIFA: Lightweight Fiber-based Antenna for Small Sat-Compatible Radiometry
NASA’s Space Technology Mission Directorate funds the NIAC program, as it is responsible for developing the agency’s new cross-cutting technologies and capabilities to achieve its current and future missions.
To learn more about NIAC, visit:
https://www.nasa.gov/niac
-end-
Jimi RussellHeadquarters, Washington216-704-2412james.j.russell@nasa.gov

NASA Engineers Push Limits of Physics to Focus Light

Source: NASA

Photon sieves focus extreme ultraviolet light and can enable Sun science.

A pair of precision-orbiting small satellites will attempt to capture the first views ever of small-scale features near the surface of the Sun that scientists believe drive the heating and acceleration of solar wind.
Heliophysicist Dr. Doug Rabin at NASA’s Goddard Space Flight Center in Greenbelt, Maryland, said photon sieves, a technology that can focus extreme ultraviolet light, should be able to resolve features 10 to 50 times smaller than what can be seen today with the Solar Dynamics Observatory’s EUV imager.

To be most effective, however, they must be wide, super-thin, and etched with precise holes to refract light. Working in Goddard’s Detector Development Laboratory, Goddard engineer Kevin Denis developed new ways to create wider and thinner membranes from wafers of silicon and niobium. Each advancement so far has required additional steps to protect the resulting sieves, such as leaving a honeycomb of thicker material to support the membrane and prevent tearing.
“It’s a sheer physical challenge to construct sieves with such precision,” said Goddard Heliophysicist Dr. Doug Rabin. “Their smallest features are a 2-microns across with a 2-micron gap between perforations, that’s about the size of most bacteria.”

Etched with from the center with ever smaller rings of holes, sieves are built to refract light similarly to Fresnel lenses used in lighthouses. Extreme ultraviolet light passing through this sieve is bent gradually inward to a distant camera. Thin membranes matter for solar science because these sieves transmit more light than thicker materials, Denis said.
He and fellow engineer Kelly Johnson successfully produced a 3-inch (8-cm) diameter silicon sieve, a mere 100 nanometers thick. Now they are experimenting with niobium membranes which can further improve light-gathering efficiency because they transmit up to seven times more light than silicon. They have successfully etched a 5-inch (13 cm) diameter niobium sieve just 200 nanometers thick.  
Denis takes inspiration from working closely with scientists to overcome barriers to advancing their field, he said. “They have done a great job using the sieves in near-term science applications while we push the technology for larger and more capable missions.”

Photon sieves cut from materials as thick as 25 microns are already part of the technology demonstration VISORS – Virtual Super Optics Reconfigurable Swarm – CubeSat mission, expected to launch in 2024. VISORS consists of one compact satellite about the size of a briefcase outfitted with sieves to refract light onto a receiver on a second satellite 130 feet (40 m) away. Maintaining these spacecraft’s high-precision orbit and developing a sunshade are the focus of other Goddard IRAD project.
VISOR’s success could pave the way for a larger future mission, with spacecraft separation measured in kilometers, employing the greater resolution of Denis’s thinner sieves once they are ready for spaceflight.
Another larger photon sieve will be used to calibrate the MUSE – Multi-slit Solar Explorer – spectrometer expected to launch in 2027. 
Denis’s work was highlighted in Physics Today, a publication of the American Institute for Physics, and has resulted with two patents already with a third submitted. Goddard Chief Technologist Peter Hughes awarded Denis the FY23 IRAD Innovator of the Year Award during the program’s annual poster session held Nov. 15.
While he continues to push the limits of engineering, Denis said he is looking forward to the MUSE and VISORS launches. “It’s a great motivation to see how they are going to be used for new science even as we continue to improve.”
By Karl B. Hille
NASA’s Goddard Space Flight Center in Greenbelt, Md.