Skip to content

BSL v1.0 Delivery and Deployment Review

ckrup edited this page Sep 18, 2025 · 42 revisions

1. Agenda

  1. Agenda
  2. Review Board
  3. Software Overview
  4. Requirements
  5. Improvements
  6. Defect Corrections
  7. Sustaining Activities
  8. Other
  9. Additional Testing
  10. Test Case Explanations
  11. Software Status
  12. Open Defect Summary
  13. Action Item Status
  14. Deviations

2. Review Board

Role
Review Board Chair Jamie Seung Shin
MGSS Chief Engineer Michele Vogt
MGSS Deputy Chief Engineer Kyran Owen-Mankovich
MGSS Assurance Engineer Eva Bokor
MGSS Cybersecurity Engineer Mike Pajevski
ASEC/ASIS SE Ken Gieselman
Task Manager Chris Krupiarz
Task Lead Brian Sipos

3. Software Overview

The BPSec Library (BSL) is a software library (v1.0) and an implementation of Bundle Protocol Security (BPSec), which is the standardized mechanism for BPv7 bundle-layer security as specified in the IETF RFC 9172. The BPv7 transport protocol was developed as part of an overall Delay-Tolerant Networking (DTN) architecture for data exchange in challenging communications environments. BPv7 has been baselined for use in a variety of NASA and other space agency missions such as NASA’s LunaNet and ESA’s Moonlight projects, and has been recommended for a variety of other IOAG and CCSDS space-networked architectures and functions.

The BPv7 protocol data unit is the Bundle, and bundles are comprised of multiple Blocks of information. An application that produces, processes, and/or delivers bundles in compliance with the BPv7 specification is called a Bundle Protocol Agent (BPA). BPSec defines special extension blocks that carry cryptographic information related to other blocks in the same bundle. All standards-compliant BPAs must be able to process BPSec blocks in a received bundle if required by the security policy of the BPA. This project will create a BPSec Library (BSL) that implements a general-purpose BPSec security block processor.

Release information for the software can be found in the BSL docs repository.

Title Document Number Status
BPSec Task Implementation Plan DOC-005726 Released
BPSec Concept of Operations DOC-005727 Released
BPSec Software Requirements Document DOC-005735 Released
BPSec Software Design Document DOC-005734 Released
BPSec Software Interface Specifications DOC-005735 Released
BPSec 1.0 Test Specification DOC-005849 Released
BPSec 1.0 Test Plan DOC-005848 Released
BPSec 1.0 Test Report DOC-005850 In Review
BPSec 1.0 RDD DOC-005923 In Review
BPSec Product Guide DOC-005922 In Review
BPSec User Guide DOC-005921 In Review

4. Requirements

Note: During testing, BSL-GEN-2-3 was determined to violate the model for BPSpec where the Policy Provider should be the one telling the BSL what to do and the BSL should simply respond. Therefore, it was not tested and is removed from the SRD. The text of BSL-GEN-2-3 is shown here:

Rqmt ID Title Description
BSL-GEN-2-3 Validate SOP Uniqueness The BSL shall ensure that security operations in a bundle are unique.
Rqmt ID Description Verification Procedure ID Test Status
BSL-GEN-1-0 The BSL shall be compliant with RFC 9172. BSL_1 (RFC Compliance) Pass
BSL-GEN-1-1 The BSL shall impose a deterministic processing order for all security blocks. BSL_2 (Deterministic Processing Order) Pass
BSL-GEN-2-0 The BSL shall construct security blocks for inclusion in a bundle. BSL_3 (Security Block Inclusion) Pass
BSL-GEN-2-1 The BSL shall add security operations to a security block. BSL_4 (Security Operations) Pass
BSL-GEN-2-2 The BSL shall determine whether a new security block can be added to the bundle when adding a security operation to a bundle. BSL_5 (Adding Block to Bundle) Pass
BSL-GEN-3-0 The BSL shall remove security operations from a bundle. BSL_7 (Removing Security Operations) Pass
BSL-GEN-3-1 The BSL shall determine when a security block should be removed from a bundle. BSL_8 (Bundle Removing Block) Pass
BSL-GEN-3-2 The BSL shall inform the BPA to discard a security block when all security operations for that block have been removed. BSL_9 (Inform BPA) Pass
BSL-GEN-4-0 The BSL shall read non-security block contents as provided by the BPA. BLS_10 (Reading Non Security Block) Pass
BSL-GEN-5-0 The BSL shall provide updated block contents to the BPA. BSL_11 (Updating Block Contents) Pass
BSL-GEN-6-0 The BSL shall encode the BTSD produced for a security block in compliance with RFC9172 encodings. BSL_12 (Encode BTSD) Pass
BSL-GEN-7-0 The BSL shall decode the BTSD of a RFC9172 encoded security block. BSL_13 (Decode BTSD) Pass
BSL-GEN-8-0 The BSL shall determine what security role (if any) the local node shall have for a given security operation. BSL_14 (Node Security Role) Pass
BSL-GEN-9-0 The BSL shall perform processing action(s) in response to security operation lifecycle events when required by policy. BSL_15 (Operation Lifecycle Events) Pass
BSL-GEN-9-1 The BSL shall request that a BPA remove a security block when required by policy. BSL_16 (BPA Removing Block) Pass
BSL-GEN-9-2 The BSL shall request that a BPA delete a security target block when required by policy. BSL_17 (BPA Deleting Block) Pass
BSL-GEN-9-3 The BSL shall request that the BPA delete all security operations represented by a security block when required by policy. BSL_18 (BPA Deleting Operations) Pass
BSL-GEN-9-4 The BSL shall request that the BPA delete a bundle when required by policy. BSL_19 (BPA Deleting Bundle) Pass
BSL-GEN-9-5 The BSL shall generate a bundle status report when required by policy. BSL_20 (Bundle Status Report) Pass
BSL-SSF-1-0 The BSL shall generate cryptographic materials based on bundle information and local policy. BSL_21 (Generate Cryptographs) Pass
BSL-SSF-1-1 The BSL shall determine the success or failure of any attempted cryptographic function. BSL_22 (Success Cryptographic Function)  Pass
BSL-SSF-2-0 The BSL shall alter the contents of non-security blocks to incorporate cryptographic outputs in accordance with RFC 9173. BSL_23 (RFC Compliant Cryptographs) Pass
BSL-SSF-2-1 The BSL shall place cryptographic material in security block security result fields in accordance with RFC 9172 and RFC 9173. BSL_24 (Security Block Result Fields) Pass
BSL-SSF-3-0 The BSL shall extract the set of bundle and block data needed to assemble security context inputs. BSL_25 (Extracting Bundle Block Data) Pass
BSL-SSF-3-1 The BSL shall retrieve key-related parameters required by key-based security contexts. BSL_26 (Retrieving Key Parameters) Pass
BSL-SSF-4-0 The BSL shall support the security contexts identified in RFC 9173. BLS_27 (Supporting Security Contexts) Pass
BSL-SSF-4-1 The BSL shall support the use of the BCB-AES-GCM default security context [RFC 9173] for BCB-confidentiality security operations. BSL_28 (Supporting BCB AES GCM) Pass
BSL-SSF-4-2 The BSL shall support the use of the BIB-HMAC-SHA default security context [RFC 9173] for bib-integrity security operations. BSL_29 (Supporting BIB HMAC SHA) Pass
BSL-ERR-1-0 The BSL shall indicate to the BPA the result (e.g. success, failure, or error) of each attempted security operation. BSL_30 (Results of Operation) Pass
BSL-ERR-1-1 The BSL shall verify the security operations of a security block for which the BPA is the Security Verifier as defined in RFC 9172. BSL_31 (BPA Security Verifier) Pass
BSL-ERR-1-2 The BSL shall verify that every security block required by security policy at the current node is present in the bundle. BSL_32 (Security Block Node) Pass
BSL-ERR-1-3 The BSL shall have the ability to inform the BPA that a block is unintelligible using Reason Code 8 as defined in RFC 9171. BSL_33 (Reason Code 8) Pass
BSL-ERR-2-0 The BSL shall collect metrics indicating health and performance. BSL_34 (Health Performance Metrics) Pass
BSL-ERR-2-1 The BSL shall write diagnostic information to a configurable logging system. BSL_35 (Configurable Logging System) Pass
BSL-ERR-3-0 The BSL shall establish abort procedures to recover from security operation failures. BSL_36 (Abort Procedures) Pass
BSL-ERR-3-1 The BSL shall report on the failure of any interface to perform a requested operation. BSL_37 (Interface Failure) Pass
BSL-ERR-3-2 The BSL shall cease processing related security operations when there is a processing error associated with those operations. BSL_38 (Processing Error) Pass
BSL-ERR-4-0 The BSL shall implement fault-injection interfaces. BSL_39 (Fault Injection Interfaces) Pass
BSL-BIN-1-0 The BSL shall use a BPA interface to query node-specific BPA configuration items. BSL_40 (Query BPA Items) Pass
BSL-BIN-2-0 The BSL shall use a BPA interface to query specific processing activities which are executed as part of processing a security operation. BSL_41 (Query BPA Processing Activities) Pass
BSL-BIN-3-0 The BSL shall use a BPA interface to request the BPA to remove a bundle. BSL_42 (Remove BPA Bundle) Pass
BSL-BIN-4-0 The BSL shall use a BPA interface to query what block types exist in a bundle. BSL_43 (Query Existing Block Types) Pass
BSL-BIN-4-1 The BSL shall use a BPA interface to query what block numbers are present in a bundle. BSL_44 (Query Block Numbers) Pass
BSL-BIN-5-0 The BSL shall use a BPA interface to request, from the BPA, block contents associated with a specific block. BSL_45 (Request BPA Block Contents) Pass
BSL-BIN-5-1 The BSL shall use a BPA interface to query block-type-specific data in a piecewise, sequential manner. BSL_46 (Query Block Specific Data) Pass
BSL-BIN-6-0 The BSL shall use a BPA interface to have the BPA add new blocks to a bundle. BSL_47 (Add New BPA Blocks) Pass
BSL-BIN-7-0 The BSL shall use a BPA interface to have the BPA remove existing blocks from a bundle. BSL_48 (Remove BPA Blocks) Pass
BSL-BIN-8-0 The BSL shall use a BPA interface to modify the block-type-specific data of non-security, non-primary blocks. BSL_49 (Modify Block Specific Data) Pass
BSL-BIN-9-0 The BSL shall use a BPA interface to have a provided bundle status report transmitted by the BPA. BSL_50 (Transmitting Bundle Report) Pass
BSL-BIN-10-0 The BSL shall use a BPA interface for encoding complex structures (such as Endpoint IDs). BSL_51 (Encoding Complex Structures) Pass
BSL-BIN-10-1 The BSL shall use a BPA interface for decoding complex structures (such as Endpoint IDs). BSL_52 (Decoding Complex Structures) Pass
BSL-CIN-1-0 The BSL crypto interface shall identify private key material indirectly. BSL_53 (Identify Private Key) Pass
BSL-CIN-1-2 The BSL crypto interface shall retrieve certificates. BSL_54 (Crypto Retrieving Certificates) Pass
BSL-CIN-1-3 The BSL crypto interface shall store certificates. BSL_55 (Crypto Storing Certificates) Pass
BSL-CIN-2-0 The BSL crypto interface shall update statistics associated with keys. BSL_56 (Crypto Updating Statistics) Pass
BSL-CIN-3-0 The BSL crypto interface shall process all cryptographic primitives (such as symmetric and asymmetric cipher operations, key agreement and key derivation, and random number generation). BSL_57 (Processing Crypto Primitives) Pass
BSL-PIN-1-0 The BSL policy interface shall determine the security operations to be performed by the local BPA for a given set of blocks in a bundle. BSL_58 (Policy For Local BPA) Pass
BSL-PIN-1-1 The BSL policy interface shall determine what security roles are performed by the local BPA for a given security operation. BSL_59 (Policy Determining Security Roles) Pass
BSL-PIN-1-2 The BSL policy interface shall determine what security operations are expected to exist in a given bundle. BSL_60 (Policy Determining Security Operations) Pass
BSL-PIN-2-0 The BSL policy interface shall query security context information for a given security operation. This information includes the security context identifier and parameters. BSL_61 (Query Security Context) Pass
BSL-PIN-2-1 The BSL policy interface shall query what policy-provided parameters should override parameters present in security blocks. BSL_62 (Query Policy Parameters) Pass
BSL-PIN-3-0 The BSL policy interface shall provide specific processing activities which are executed as part of processing a security operation. BSL_63 (Specific Processing Activities) Pass
BSL-TIN-1-0 The BSL telemetry interface shall allow a host to query metrics from the BSL. BSL_64 (Telemetry Host Query Metrics) Pass
BSL-LIN-1-0 The BSL logging interface associate logging levels with log entries, to include the levels of Critical, Error, Warning, Notification, and Debug. BSL_65 (Logging Levels) Pass
BSL-LIN-2-0 The BSL logging interface annotate log entries with metadata related to time and process doing the logging. BSL_66 (Log Entries With Metadata) Pass
BSL-LIN-3-0 The BSL logging interface shall truncate the length of individual log entries to stay within configured limits. BSL_67 (Truncate Log Entries) Pass
BSL-LIN-4-0 The BSL logging interface shall determine whether an attempt to log an event succeeded. BSL_68 (Successful Log Attempt) Pass
BSL-SVC-1-0 The BSL shall request from all policy providers the specific policy associated with a bundle at the current node. BSL_69 (Policy At Current Node) Pass
BSL-SVC-1-1 The BSL shall validate and prioritize security policy statements before applying them to a bundle. BSL_70 (Validating Policy Statements) Pass
BSL-SVC-2-0 After the BSL validates security policy for a bundle, the BSL shall coordinate functions of the associated security context to apply that rule. BSL_71 (Coordinate Functions) Pass
BSL-SVC-3-0 The BSL shall perform the processing action(s) provided by a security policy rule when a security processing failure occurs. BSL_72 (Processing Actions From Failure) Pass
BSL-CFG-1-0 The BSL shall establish a catalog of settings that users may configure at run-time. BSL_73 (Settings Catalog) Pass
BSL-CFG-2-0 The BSL shall allow parameterization via configuration files and environment variables. BSL_74 (Parameterization Via Configuration) Pass
BSL-CFG-3-0 The BSL shall embed build information into runtime artifacts BSL_75 (Embedding Information) Pass
BSL-CFG-4-0 The BSL shall embed version into the executable, and be identified when running the application. BSL_76 (Embedding Version) Pass
BSL-CFG-5-0 The BSL shall provide a catalog of configurable compile-time items. BSL_77 (Compile Time Catalog) Pass
BSL-CFG-6-0 The BSL shall provide a catalog of configurable run-time items. BSL_78 (Run Time Catalog) Pass
BSL-CFG-7-0 The BSL shall support parameterization by compiler command line arguments and configuration files. BSL_79 (Compiler Command Line Arguments) Pass
BSL-PFR-1-0 The BSL shall compile using strict compiler flags for error and warning checks. BSL_80 (Strict Compiler Flags) Pass
BSL-PFR-2-0 The BSL telemetry interfaces shall support asynchronous operation. BSL_81 (Supporting Asynchronous Operations) Pass
BSL-SEC-1-0 The BSL shall delegate all cryptographic functions to an external library accessibly only through the crypto interface. BSL_82 (Delegate Crypto Functions) Pass
BSL-SEC-2-0 The BSL shall delegate the handling and storage of all cryptographic key material to external libraries. BSL_83 (Delegate Handling And Storage) Pass
BSL-ADP-1-0 The BSL shall provide an API to register security contexts. BSL_84 (Register Security Contexts) Pass
BSL-ADP-2-0 The BSL shall provide an API to register policy providers. BSL_85 (Register Policy Providers) Pass
BSL-ADP-3-0 The BSL shall use an abstraction layer to avoid OS-specific operations. BSL_86 (Use Abstraction Layer) Pass
BSL-ADP-4-0 The BSL crypto function interface shall be stateless. BSL_87 (Stateless Crypto Function) Pass

5. Improvements

None

6. Defect Corrections

None

7. Sustaining Activities

None

8. Other

None

9. Additional Testing

None

10. Test Case Explanations

All tests passed.

11. Software Status

Component Code Size SLOC Added SLOC Deleted SLOC Changed
BSL 7151 7151 0 0
Code Coverage
Source backend coverage: 86.1%
Source crypto coverage: 87.3%
Source policy_provider coverage: 94.3%
Source security_context coverage: 70.9%
Source mock_bpa coverage: 50.5%
CM Tool CM Repository
Git https://github.com/NASA-AMMOS/BSL/

Static Analysis results:

CodeQL (all issues closed): https://github.com/NASA-AMMOS/BSL/security/code-scanning SonarCloud Analysis (all Security, Reliability, and Blocker-severity issues closed) https://sonarcloud.io/project/issues?issueStatuses=OPEN%2CCONFIRMED&id=NASA-AMMOS_BSL

ICA-48244: https://jira.jpl.nasa.gov/browse/ICA-48244

12. Open Defect Summary

No open defects

The GitHub ticket list can be found here that shows bugs that were found and closed since TRR (23 in total): https://github.com/orgs/NASA-AMMOS/projects/12/views/2

13. Action Item Status

AI Description Status
MGSSAITS-1892 SQA BPSec 1.0 TRR: review and release the test documents Closed on 09.16.2025

Note: two additional requests from the TRR are not complete:

  • Set up a meeting to go over software classification and required documentations
  • GSFC to perform testing with initial BSL code

14. Deviations

The following are deviations from the MIMTaR:

  • Release Plan was waived
  • The CDR material serves as the Design Document

Clone this wiki locally